CVE-2026-28830
- EPSS 0.01%
- Veröffentlicht 11.05.2026 20:07:33
- Zuletzt bearbeitet 12.05.2026 19:47:43
A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
CVE-2026-28918
- EPSS 0.05%
- Veröffentlicht 11.05.2026 20:07:30
- Zuletzt bearbeitet 13.05.2026 13:57:36
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Parsing a maliciously crafted file may lead to an unexpected app ter...
CVE-2026-39870
- EPSS 0.03%
- Veröffentlicht 11.05.2026 20:07:30
- Zuletzt bearbeitet 13.05.2026 14:39:49
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Processing a maliciously crafted image may corrupt process memory.
CVE-2026-28959
- EPSS 0.06%
- Veröffentlicht 11.05.2026 20:07:29
- Zuletzt bearbeitet 13.05.2026 14:36:21
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app ...
CVE-2026-28909
- EPSS 0.04%
- Veröffentlicht 30.04.2026 22:00:01
- Zuletzt bearbeitet 04.05.2026 18:22:48
Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
CVE-2026-28815
- EPSS 0.07%
- Veröffentlicht 03.04.2026 01:32:28
- Zuletzt bearbeitet 13.04.2026 17:50:58
A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto ve...
CVE-2025-43236
- EPSS 0.01%
- Veröffentlicht 02.04.2026 18:27:28
- Zuletzt bearbeitet 03.04.2026 17:58:15
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.
CVE-2025-43257
- EPSS 0.02%
- Veröffentlicht 02.04.2026 18:25:34
- Zuletzt bearbeitet 03.04.2026 17:57:19
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.
CVE-2024-40849
- EPSS 0.08%
- Veröffentlicht 02.04.2026 18:22:35
- Zuletzt bearbeitet 03.04.2026 19:39:14
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.
CVE-2024-44303
- EPSS 0.09%
- Veröffentlicht 02.04.2026 18:21:49
- Zuletzt bearbeitet 03.04.2026 17:53:39
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected parts of the file system.