PatchSiren

Apple CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43722

A vulnerability, CVE-2026-43722, was addressed by Apple through improved input sanitization. This issue affected various Apple operating systems, including iOS, iPadOS, and macOS. An application may have been able to leak sensitive kernel state due to this vulnerability. Apple has released updates to fix this issue, which are iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and mac [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43718

A stack overflow vulnerability was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability can be triggered by processing maliciously crafted web content, potentially leading to an unexpected Safari crash. Users of affected Apple products should apply the latest security upda [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43717

A use-after-free issue was addressed with improved memory management in Safari. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. The vulnerability could lead to an unexpected Safari crash when processing maliciously crafted web content. Users of affected products should apply updates to prevent potential crashes.

HIGH Apple CVE published 2026-06-29

CVE-2026-43715

A use-after-free issue was addressed with improved memory management in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption. This issue affects multiple Apple products and could allow an attacker to execute arbitrary code on affected systems. Defenders sho [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43713

A permissions issue was addressed with additional restrictions in various Apple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue allows sensitive data to potentially leak when visiting a website. Apple has addressed this issue with additional restrictions in the specified security updates. Users of Apple products should apply the latest security updates to prevent pot [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43712

Apple has addressed a vulnerability in multiple products that could lead to an unexpected process crash when processing maliciously crafted web content. This issue was fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability is related to improved memory handling. Users of Apple products, particularly those who use Safari, iOS, iPa [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43709

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability can lead to an unexpected process crash when processing maliciously crafted web content. Users of Apple products should apply the latest security updates to prevent potential crashes.

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43708

A malicious website may exfiltrate data cross-origin due to an input validation issue addressed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. This issue has a CVSS score of 4.3 and is considered Medium severity. The vulnerability allows a malicious website to potentially exfiltrate data cross-origin.

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43707

A memory corruption issue was addressed with improved memory handling in Apple products. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability involves a memory corruption issue that could lead to an unexpected process crash when processing maliciously crafted web content. Users should apply the latest security upd [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43706

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability could lead to an unexpected process crash when processing maliciously crafted web content. This issue has a medium severity with a CVSS score of 6.5. Users of Apple de [truncated]

HIGH Apple CVE published 2026-06-29

CVE-2026-43705

A type confusion issue was addressed with improved checks in various Apple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This issue could lead to memory corruption when processing maliciously crafted web content. The vulnerability's impact is considered High, with a CVSS score of 8.8. Users of Apple products should apply the latest security updates to prevent potential memor [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43704

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. A malicious web extension may be able to cause an unexpected process crash. Users of Apple products, particularly those using Safa [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43703

Apple has addressed a memory handling issue in multiple products, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue could lead to an unexpected process crash when processing maliciously crafted web content. This vulnerability, tracked as CVE-2026-43703, has a CVSS score of 6.5, indicating a medium severity level. The affected products include iOS, iPadOS, macOS Sequoia, macOS Sonoma, ma [truncated]

HIGH Apple CVE published 2026-06-29

CVE-2026-43701

Apple has addressed a vulnerability in multiple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue was addressed with improved checks, fixing a problem where a malicious website may be able to process restricted web content outside the sandbox. This vulnerability has a high severity with a CVSS score of 7.1. Users of affected products should apply security updates immed [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43700

CVE-2026-43700 is a cross-origin issue affecting various Apple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue was addressed with improved tracking of security origins. This vulnerability has a CVSS score of 6.5 and can lead to disclosure of sensitive user information if exploited. Users of affected Apple products should apply available updates to prevent potential d [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43699

A use-after-free issue was addressed with improved memory management in Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This issue can lead to an unexpected process crash when processing maliciously crafted web content. The vulnerability affects users of Apple products and has been addressed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

MEDIUM Apple CVE published 2026-06-29

CVE-2026-43663

Apple has addressed a memory handling issue in multiple products, including Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. The issue could lead to an unexpected process crash when processing maliciously crafted web content. This vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Users of Apple products, particularly tho [truncated]

MEDIUM Apple CVE published 2026-06-29

CVE-2026-39872

Apple has addressed a memory handling issue in multiple products, including Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. The issue could lead to an unexpected process crash when processing maliciously crafted web content. This vulnerability is classified as a denial-of-service (DoS) issue, which could potentially be used to cause service disr [truncated]

CRITICAL Apple CVE published 2026-06-29

CVE-2026-39868

A critical vulnerability, CVE-2026-39868, was addressed by Apple through improved input validation. This issue affects multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. An application may exploit this vulnerability to cause unexpected system termination or corrupt kernel memory. The vulnerability has a CVSS score of 9.1 and is considered critical. Organizations a [truncated]

HIGH Apple CVE published 2026-06-11

CVE-2025-46315

CVE-2025-46315 is a HIGH-severity vulnerability (CVSS Score: 7.5) affecting macOS, which was publicly disclosed on 2026-06-11. The issue involves a permissions problem that was resolved with additional restrictions in macOS Tahoe 26.1. Successful exploitation could allow an app to access protected user data. Apple has provided a vendor advisory [ref-4] detailing the fix.

MEDIUM Apple CVE published 2026-06-11

CVE-2025-46313

CVE-2025-46313 is a medium-severity vulnerability (CVSS Score: 5.5) that was publicly disclosed on 2026-06-11T19:16:34.603Z and last modified on 2026-06-12T22:16:47.890Z. The vulnerability is related to a logging issue that was addressed with improved data redaction in macOS Tahoe 26.1. According to the CVE description, an app may be able to access sensitive user data due to this issue. The CVE record can [truncated]

MEDIUM Apple CVE published 2026-06-11

CVE-2025-46308

CVE-2025-46308 is a medium-severity vulnerability (CVSS Score: 5.3) affecting iOS, iPadOS, and macOS. An authorization issue was addressed with improved state management, fixing a bug that allowed an app to leak sensitive user information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4.

MEDIUM Apple CVE published 2026-06-11

CVE-2025-46293

CVE-2025-46293 is a medium-severity vulnerability in Apple macOS, addressed in macOS Sequoia 15.4. The issue was related to improved handling of symlinks. An app may be able to access protected user data. The CVSS score for this vulnerability is 5.5.

MEDIUM Apple CVE published 2026-06-11

CVE-2025-43339

CVE-2025-43339 is a MEDIUM-severity access issue vulnerability addressed by Apple in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data. The issue was publicly disclosed on [**cve-org**](https://www.cve.org/CVERecord?id=CVE-2025-43339) and further details can be found on [**nvd**](https://nvd.nist.gov/vuln/detail/CVE-2025-43339).

MEDIUM Apple CVE published 2026-06-11

CVE-2025-43278

CVE-2025-43278 is a medium-severity vulnerability (CVSS Score: 5.5) that was addressed with improved handling of symlinks. The issue is fixed in macOS Sequoia 15.4. According to the CVE description, an app may be able to access protected user data. The CVE was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH Apple CVE published 2026-06-11

CVE-2025-31272

CVE-2025-31272 is a HIGH severity vulnerability in macOS Sequoia 15.4. The issue was addressed with improved checks. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges. The CVSS score for this vulnerability is 7.8.

MEDIUM Apple CVE published 2026-06-11

CVE-2025-30459

CVE-2025-30459 is a medium-severity privacy issue in Apple macOS Sequoia 15.4. The vulnerability allowed an app to potentially access sensitive user data due to the presence of vulnerable code, which has since been removed. This issue was publicly disclosed on [cvePublishedAt] and last modified on [cveModifiedAt].

MEDIUM Apple CVE published 2026-06-11

CVE-2025-30431

CVE-2025-30431 is a medium-severity vulnerability in Apple macOS, allowing malicious apps to access private information. The issue was addressed with improved checks and is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5.

HIGH Apple CVE published 2026-06-11

CVE-2025-24284

CVE-2025-24284 is a HIGH severity vulnerability in Apple macOS, with a CVSS score of 8.8. The issue was addressed with improved checks to prevent unauthorized actions and is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox due to this vulnerability.

MEDIUM Apple CVE published 2026-06-11

CVE-2025-24268

CVE-2025-24268 is a medium-severity vulnerability (CVSS Score: 5.5) affecting macOS Sequoia. The issue involves a parsing problem with directory paths that was resolved through improved path validation, fixed in macOS Sequoia 15.4. Successful exploitation could allow an app to access sensitive user data.