Blog

The Apple Security Update Review for September 2026

September 16, 2026
Dustin Childs

Welcome back to our monthly look at Apple security patches. This release shows Apple is not immune to the new normal of AI-assisted vulnerability discovery as they release patches for 273 total CVEs.

For the September 2026 release, Apple released 273 unique CVEs across macOS 27 (Golden Gate), macOS Sequoia 15.8, macOS Tahoe 26.7, iOS / iPadOS 27, visionOS 27, watchOS 27, tvOS 27, iOS / iPadOS 26.7, Safari 27, and Xcode 27. This patch release actually happened a couple of days ago, but since Apple doesn’t provide CVSS scores or other severity information, it takes a couple of days to understand the full severity. Even with the additional time, there are many CVEs without a severity score. However, looking at the one that do have severity assigned by NVD or CISA-ADP, there are a few that truly stand out, including one under active exploit.

CVE-2026-65400 — Screen Sharing Server (9.8 CRITICAL, ⚠ CISA KEV).
This bug is confirmed by CISA to be actively exploited. A network attacker can authenticate to Screen Sharing without valid credentials, without user interaction. This component was first patched on August 6 and relisted in v27 as macOS 27/Tahoe 26.7 now carries the fix.

CVE-2026-65414 — Bluetooth (9.8 CRITICAL).
This is the highest-scored non-exploited bug in the release. It’s remote, network-vector arbitrary code execution with no privileges or interaction, and CISA tagged it "automatable: yes, technical impact: total." It spans all eight OS platforms, which is the broadest-reach critical vulnerability in the release and the most likely candidate to become a KEV entry.

CVE-2026-65346 — ImageIO (8.8 HIGH).
The bug sits at the top of the HIGH tier and is the most dangerous remote content bug: processing a malicious image leads to arbitrary code execution. ImageIO is the canonical zero-/one-click surface (images auto-rendered in Messages, previews), so it carries high real-world weaponization potential.

Two honorable mentions that matter because of a data caveat: CVE-2026-84607 (AVEVideoEncoder) — a sandbox-to-kernel arbitrary-code-execution bug — and CVE-2026-43790 (Kernel) — remote kernel memory corruption — are arguably more severe by impact than #3, but NVD hasn't scored either yet (both TBD), so they don't rank on the current evidence. Also worth noting: CVE-2026-43692 (CUPS) remote code execution and CVE-2026-84568 (autofs) root RCE both sit at the top of the HIGH band.

Here’s the full table of Apple patches and the products they affect:

Apple Security Updates — September 14, 2026 (v27)
273Total CVEs
134Scored
139TBD
2CRITICAL
46HIGH
84MEDIUM
2LOW

CVSS is the NVD primary score where available, otherwise CISA-ADP secondary; TBD = NVD has not scored it yet (most v27 CVEs are still under analysis). ⚠ KEV marks CVEs in CISA's Known Exploited Vulnerabilities catalog.

Apple security release — September 14, 2026 (version 27), 273 CVEs. CVSS/Severity from NVD (National Vulnerability Database) as of Sept 16, 2026. CVE IDs link to NVD. "Yes/No" indicates whether each update is affected.
CVE IDComponentImpactCVSSSeverity iOS / iPadOS 27 iOS / iPadOS 26.7 macOS 27 (Golden Gate) macOS Tahoe 26.7 macOS Sequoia 15.8 tvOS 27 watchOS 27 visionOS 27 Safari 27 Xcode 27
CVE-2026-65400 Screen Sharing Server An attacker on the network may be able to authenticate to Screen Sharing without valid credentials 9.8⚠ KEV CRITICAL NoNoYesYesNoNoNoNoNoNo
CVE-2026-65414 Bluetooth A remote attacker may be able to cause unexpected app termination or arbitrary code execution 9.8CRITICAL YesYesYesYesYesYesYesYesNoNo
CVE-2026-43692 CUPS A remote user may cause an unexpected app termination or arbitrary code execution 8.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-65346 ImageIO Processing an image may lead to arbitrary code execution 8.8HIGH NoNoNoNoYesYesYesYesNoNo
CVE-2026-43686 Kernel Connecting to a malicious NFS server may lead to kernel memory corruption 8.8HIGH YesYesYesYesYesYesYesYesNoNo
CVE-2026-65374 WebDAV Connecting to a malicious WebDAV server may result in code execution 8.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-43715 WebKit Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoYesNoNoNoNoNoNoNoNo
CVE-2026-43794 WebKit Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo
CVE-2026-65390 WebRTC Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo
CVE-2026-65391 WebRTC Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo
CVE-2026-43760 Screen Sharing Server An app may be able to access user-sensitive data 8.6HIGH NoNoNoYesNoNoNoNoNoNo
CVE-2026-84581 HFS Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory 8.4HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-84535 Automator An app may be able to break out of its sandbox 8.2HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-84516 CUPS Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory 8.1HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-65415 Kernel A local user may be able to cause unexpected system termination or read kernel memory 8.1HIGH YesNoYesNoNoYesYesYesNoNo
CVE-2026-84568 autofs An attacker with control of a network directory server may be able to execute arbitrary code with root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-84607 AVEVideoEncoder A sandboxed app may be able to execute arbitrary code with kernel privileges 7.8HIGH YesYesYesYesYesYesYesYesNoNo
CVE-2026-84631 Bluetooth An app may be able to gain root privileges 7.8HIGH NoNoYesNoNoNoNoNoNoNo
CVE-2026-43786 CoreServices An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-84575 CoreUI Processing a maliciously crafted file may lead to unexpected app termination 7.8HIGH YesNoYesYesYesYesYesYesNoNo
CVE-2026-43691 CUPS An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-43698 CUPS An app may be able to gain root privileges 7.8HIGH NoNoYesYesNoNoNoNoNoNo
CVE-2026-84505 Directory Utility An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-65362 Disk Images An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-64758 ImageIO Processing a maliciously crafted file may lead to unexpected app termination 7.8HIGH NoYesNoNoYesNoNoNoNoNo
CVE-2026-43684 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory 7.8HIGH NoYesYesNoYesNoNoNoNoNo
CVE-2026-43689 Kernel A malicious app may be able to gain root privileges 7.8HIGH YesYesYesNoNoNoNoYesNoNo
CVE-2026-86917 Kernel An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-64712 odproxyd An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-84515 SMB Connecting to a malicious SMB server may lead to kernel memory corruption 7.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-84506 udf An app may be able to execute arbitrary code with kernel privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-64761 Accessibility An app may be able to identify what other apps a user has installed 7.5HIGH YesNoNoNoNoNoNoNoNoNo
CVE-2026-86895 CloudKit A local app may be able to read a persistent account identifier 7.5HIGH YesNoNoNoNoYesYesYesNoNo
CVE-2026-84563 CUPS An app may be able to cause unexpected system termination 7.5HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-84606 iCloud An app may be able to identify a user across reinstalls 7.5HIGH YesNoYesNoNoNoNoYesNoNo
CVE-2026-43661 ImageIO Processing a maliciously crafted image may corrupt process memory 7.5HIGH NoYesNoNoNoNoNoNoNoNo
CVE-2026-28969 IOKit An app may be able to cause unexpected system termination 7.5HIGH YesNoYesYesYesYesYesYesNoNo
CVE-2026-65343 Kernel A remote attacker may be able to cause unexpected system termination 7.5HIGH NoNoNoNoNoYesYesYesNoNo
CVE-2026-65364 Kernel A remote attacker may be able to cause unexpected system termination 7.5HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-86894 libxpc An app may be able to break out of its sandbox 7.5HIGH NoNoYesNoNoNoNoNoNoNo
CVE-2026-84543 SMB Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory 7.5HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-84553 smbx A remote attacker may be able to cause a denial-of-service 7.5HIGH NoNoYesYesYesNoNoNoNoNo
CVE-2026-28930 Spotlight An app may be able to access protected user data 7.5HIGH NoNoNoNoYesNoNoNoNoNo
CVE-2026-86904 Watch App An app may be able to track users across apps and websites without permission 7.5HIGH YesYesNoNoNoNoYesNoNoNo
CVE-2026-64752 CoreMedia Processing a maliciously crafted image may lead to arbitrary code execution 7.3HIGH YesNoYesNoNoNoNoYesNoNo
CVE-2026-84611 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption 7.3HIGH YesYesYesYesYesYesYesYesNoNo
CVE-2026-84632 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption 7.3HIGH YesYesYesYesYesYesYesYesNoNo
CVE-2026-64736 IOMobileFrameBuffer An app may be able to cause unexpected system termination or corrupt kernel memory 7.1HIGH NoNoNoNoYesYesYesYesNoNo
CVE-2026-65349 Kernel An app may be able to cause unexpected system termination or read kernel memory 6.6MEDIUM NoNoNoNoYesYesYesYesNoNo
CVE-2026-84537 SMB An app may be able to cause unexpected system termination or corrupt kernel memory 6.6MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-43788 Spotlight Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents 6.6MEDIUM NoNoYesNoNoNoNoNoNoNo
CVE-2026-86882 Accelerate Framework Processing a maliciously crafted image may lead to unexpected process termination 6.5MEDIUM YesYesYesYesYesYesYesYesNoNo
CVE-2026-84519 AppleDouble Mounting a disk image with maliciously crafted files may lead to unexpected system termination 6.5MEDIUM YesYesYesYesYesNoNoNoNoNo
CVE-2026-86879 Baseband A remote attacker may be able to cause a denial-of-service 6.5MEDIUM YesNoNoNoNoNoNoNoNoNo
CVE-2026-86885 Baseband An attacker in radio range may be able to cause unexpected system termination 6.5MEDIUM YesNoNoNoNoNoNoNoNoNo
CVE-2026-65412 CoreText Processing web content may lead to a denial-of-service 6.5MEDIUM YesYesYesYesYesNoYesYesNoNo
CVE-2026-84596 CoreText Processing a maliciously crafted font may result in the disclosure of process memory 6.5MEDIUM YesNoYesNoNoYesYesYesNoNo
CVE-2026-84597 FontParser Processing a maliciously crafted font may result in the disclosure of process memory 6.5MEDIUM YesNoYesNoNoYesYesYesNoNo
CVE-2022-3437 Heimdal A user in a privileged network position may be able to leak sensitive user information 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-28934 HFS Mounting a malicious disk image may cause unexpected system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-65347 ImageIO Processing an image may lead to a denial-of-service 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo
CVE-2026-65395 ImageIO Processing a maliciously crafted image may result in memory corruption 6.5MEDIUM YesYesYesYesYesYesNoYesNoNo
CVE-2026-43687 Kernel Connecting to a malicious NFS server may disclose kernel memory 6.5MEDIUM YesYesYesYesNoYesYesYesNoNo
CVE-2026-65330 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory 6.5MEDIUM NoNoNoNoYesYesYesYesNoNo
CVE-2026-84538 Kernel A remote attacker may be able to cause a denial-of-service 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-84588 Kernel Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory 6.5MEDIUM NoNoYesNoNoNoNoNoNoNo
CVE-2026-84487 SceneKit Processing a maliciously crafted file may result in disclosure of process memory 6.5MEDIUM YesYesYesYesYesYesYesYesNoNo
CVE-2026-43719 SMB Mounting a maliciously crafted SMB network share may lead to system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-65365 SMB Connecting to a malicious SMB share may disclose kernel memory 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-84536 SMB Connecting to a malicious SMB server may lead to unexpected system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-43677 WebDAV Connecting to a malicious WebDAV server may lead to unexpected app termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-64715 WebKit Processing maliciously crafted web content may lead to an unexpected process crash 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo
CVE-2026-64753 WebKit Processing maliciously crafted web content may disclose sensitive user information 6.5MEDIUM YesNoYesNoNoYesYesYesYesNo
CVE-2026-64787 WebKit Processing maliciously crafted web content may lead to an unexpected process termination 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo
CVE-2026-64778 WebKit History Visiting a maliciously crafted website may leak sensitive data 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo
CVE-2026-84560 Bluetooth An app may gain unauthorized access to Bluetooth 6.1MEDIUM YesNoYesNoNoYesYesYesNoNo
CVE-2026-84619 Kernel An app may be able to cause unexpected system termination or write kernel memory 6.1MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-84554 CUPS An attacker in a privileged network position may be able to cause a denial-of-service 5.9MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-43664 Accessibility An app may be able to access sensitive user data 5.5MEDIUM YesYesYesYesYesYesYesNoNoNo
CVE-2026-65404 Accounts A malicious application may be able to bypass Privacy preferences 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo
CVE-2026-84523 APFS An app may be able to cause unexpected system termination or write kernel memory 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo
CVE-2026-84586 Apple Account A malicious application may be able to leak sensitive user information 5.5MEDIUM NoNoYesNoNoNoYesNoNoNo
CVE-2026-65407 AppleAVD An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo
CVE-2026-84593 AppleKeyStore An app may be able to cause unexpected system termination 5.5MEDIUM YesNoNoNoNoNoNoNoNoNo
CVE-2026-43763 ATS An app may be able to read files outside of its sandbox 5.5MEDIUM NoNoNoYesYesNoNoNoNoNo
CVE-2026-86905 Authentication Services An app may be able to delete credentials stored in Keychain 5.5MEDIUM YesNoYesNoNoNoNoYesNoNo
CVE-2026-43737 CoreMotion An app may be able to access motion data from headphones without user consent 5.5MEDIUM YesYesYesYesYesYesYesNoNoNo
CVE-2026-43738 CoreUI Processing a maliciously crafted asset catalog may result in disclosure of process memory 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo
CVE-2026-84489 CoreUI An app may be able to cause a denial of service 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo
CVE-2026-84534 file_cmds Extracting a maliciously crafted archive may allow an attacker to write arbitrary files 5.5MEDIUM YesYesYesYesYesNoNoYesNoNo
CVE-2026-65409 Foundation An app may be able to cause a denial of service 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo
CVE-2026-64756 Image Capture An app may be able to access user-sensitive data 5.5MEDIUM YesNoYesYesYesNoNoNoNoNo
CVE-2026-64760 IOSurfaceAccelerator An app may be able to leak sensitive kernel state 5.5MEDIUM YesNoYesNoNoYesYesYesNoNo
CVE-2026-65401 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM NoNoYesYesNoNoNoNoNoNo
CVE-2026-65402 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo
CVE-2026-65405 Kernel An app may be able to determine kernel memory layout 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo
CVE-2026-84517 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-84521 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesNoNoYesNoNo
CVE-2026-86903 Kernel An app may be able to disclose kernel memory 5.5MEDIUM YesNoYesNoNoYesYesYesNoNo
CVE-2026-86883 Managed Configuration An app may be able to access sensitive user data 5.5MEDIUM YesNoNoNoNoNoNoYesNoNo
CVE-2026-43741 Messages An app may be able to access protected user data 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-84491 Photos Storage An app may be able to access sensitive user data 5.5MEDIUM YesYesYesNoNoYesYesYesNoNo
CVE-2026-84576 QuartzCore An app may be able to access sensitive user data 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-84555 Sandbox An app may be able to access sensitive user data 5.5MEDIUM NoNoYesNoYesNoNoNoNoNo
CVE-2026-65413 SceneKit An app may be able to cause a denial of service 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-28937 Terminal An app may be able to access sensitive user data 5.5MEDIUM NoNoYesNoNoNoNoNoNoNo
CVE-2026-64718 WebKit Canvas Processing maliciously crafted web content may lead to an unexpected Safari crash 5.5MEDIUM YesYesYesNoNoNoNoYesYesNo
CVE-2026-65393 Xcode IDE An app may be able to access user-sensitive data 5.5MEDIUM NoNoYesNoNoNoNoNoNoYes
CVE-2026-84617 XPC An app may be able to access sensitive user data 5.5MEDIUM YesYesYesYesYesYesNoNoNoNo
CVE-2026-64788 IOGPUFamily Processing maliciously crafted web content may lead to memory corruption 5.4MEDIUM NoNoNoNoNoNoYesYesNoNo
CVE-2026-65341 WebKit Processing maliciously crafted web content may lead to memory corruption 5.4MEDIUM NoNoNoNoNoYesYesYesNoNo
CVE-2026-34979 CUPS An attacker in a privileged network position may be able to cause a denial-of-service 5.3MEDIUM NoNoYesNoNoNoNoNoNoNo
CVE-2026-86876 CoreMedia A sandboxed process may be able to circumvent sandbox restrictions 5.2MEDIUM YesYesYesYesYesNoYesYesNoNo
CVE-2026-86889 Security An attacker in a privileged network position may be able to intercept network traffic 4.8MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-84492 Graphics An app may be able to cause unexpected system termination 4.7MEDIUM YesYesYesYesYesYesYesYesNoNo
CVE-2026-84630 Kernel An app may be able to cause unexpected system termination 4.7MEDIUM YesYesYesYesYesYesYesYesNoNo
CVE-2026-43690 SMB A local user may be able to read kernel memory 4.7MEDIUM NoNoYesYesYesNoNoNoNoNo
CVE-2026-84518 Safari A malicious website may be able to determine what apps a user has installed 4.3MEDIUM YesNoYesNoNoNoNoNoYesNo
CVE-2026-43795 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-64780 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-64781 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-64784 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65331 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65332 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65333 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65334 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65335 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65336 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65337 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65338 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65340 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-65351 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo
CVE-2026-64782 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 3.1LOW NoNoNoNoNoNoNoYesNoNo
CVE-2026-64779 WebKit Storage Processing maliciously crafted web content may lead to an unexpected Safari crash 3.1LOW NoNoNoNoNoNoNoYesNoNo
CVE-2026-86910 APFS An application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-86888 App Store A local app may be able to read a persistent account identifier TBDTBD YesNoYesYesNoYesYesYesNoNo
CVE-2026-84587 AppKit An app may be able to access protected user data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-20683 Apple Account An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account TBDTBD YesNoYesYesYesNoNoYesNoNo
CVE-2026-84601 Apple Intelligence An app may be able to bypass Apple Intelligence security prompts TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-65408 Apple Neural Engine An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo
CVE-2026-84520 AppleFDEKeyStore A local attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-65381 AppleMobileFileIntegrity A malicious app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84522 Archive Utility An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-84584 Archive Utility An app may be able to break out of its sandbox TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-65342 ATS An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84525 ATS An app may be able to access user-sensitive data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-65339 Audio An app may be able to leak sensitive user information TBDTBD NoNoNoNoYesYesYesYesNoNo
CVE-2026-84583 AuthKit A local app may be able to read a persistent account identifier TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84570 autofs An app may be able to bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-65410 AVEVideoEncoder An app may be able to cause unexpected system termination TBDTBD YesYesYesYesNoYesYesYesNoNo
CVE-2026-84616 AVEVideoEncoder An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-65406 BackgroundAssets An app may be able to access sensitive user data TBDTBD YesYesYesYesYesYesNoYesNoNo
CVE-2026-86878 Camera An app may be able to access sensitive user data TBDTBD YesNoNoNoNoNoNoNoNoNo
CVE-2026-84567 cd9660 An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-86893 CloudKit An app may be able to read device name TBDTBD YesNoNoNoNoYesYesYesNoNo
CVE-2026-65399 copyfile An archive may be able to bypass Gatekeeper TBDTBD YesYesYesYesYesNoYesYesNoNo
CVE-2026-86891 Core Bluetooth An app may be able to access Bluetooth device information TBDTBD NoNoYesYesYesNoYesNoNoNo
CVE-2026-43683 CoreDrag An app may be able to cause unexpected process termination or disclose process memory TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-43789 CoreMedia An app may be able to access user-sensitive data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-65344 CoreMedia Processing a maliciously crafted video file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesNoYesNoNo
CVE-2026-43702 CoreMedia Video Toolbox Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory TBDTBD NoYesNoYesYesNoNoNoNoNo
CVE-2026-84624 CoreML A sandboxed app may be able to access restricted files TBDTBD YesYesYesYesYesNoNoYesNoNo
CVE-2026-84559 CoreServices A malicious application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84574 CoreServices An app may be able to bypass Privacy preferences TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84511 CoreUI Processing a maliciously crafted asset catalog may lead to unexpected process termination TBDTBD YesNoYesYesYesYesYesYesNoNo
CVE-2026-84571 CoreUI Processing a maliciously crafted image may lead to unexpected app termination TBDTBD YesNoYesNoNoYesYesYesNoNo
CVE-2026-64790 CUPS An app may be able to gain elevated privileges TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84540 CUPS An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84541 CUPS An application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84612 DeviceCheck An app may be able to read persistent device identifiers TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84512 Disk Images Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84550 Disk Images An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84552 Disk Images An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo
CVE-2026-84565 Disk Images Processing a maliciously crafted disk image may lead to unexpected app termination TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84510 exFAT Mounting a maliciously crafted volume may lead to unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo
CVE-2026-86900 exFAT Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-86901 exFAT Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-43785 File Bookmark An app may be able to modify a file it only had permission to read TBDTBD YesNoYesYesYesYesNoYesNoNo
CVE-2026-43688 Filters Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesNoYesNoNoNoNoNoNoNo
CVE-2026-84524 FontParser Processing a maliciously crafted font file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84569 Foundation An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-86911 Foundation A malicious app may be able to bypass clickjacking protections for secure prompts TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-84618 Game Center An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84533 Heimdal An attacker in a privileged network position may be able to modify network traffic TBDTBD YesNoYesNoNoYesYesNoNoNo
CVE-2026-64714 ImageIO Processing a maliciously crafted image may lead to a denial-of-service TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-84564 ImageIO Processing a maliciously crafted image may result in disclosure of process memory TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-86869 ImageIO Processing a maliciously crafted image may lead to unexpected app termination TBDTBD NoYesYesNoNoNoNoNoNoNo
CVE-2026-43743 IOGPUFamily An app may be able to cause unexpected system termination TBDTBD NoYesNoYesNoNoNoNoNoNo
CVE-2026-65398 IOMobileFrameBuffer An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesNoYesNoNoYesYesYesNoNo
CVE-2026-65354 iWork A malicious app may be able to break out of its sandbox TBDTBD YesNoYesNoNoNoNoNoNoNo
CVE-2026-28935 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoNoNoYesYesYesYesNoNo
CVE-2026-28968 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-43790 Kernel A remote attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-65358 Kernel An app may be able to cause unexpected system termination TBDTBD YesNoYesYesYesYesYesYesNoNo
CVE-2026-65359 Kernel A local user may be able to cause unexpected system termination or read kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-65360 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-65369 Kernel A malicious application may bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-65371 Kernel An app may be able to disclose kernel memory TBDTBD NoNoNoNoYesNoNoNoNoNo
CVE-2026-65377 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84507 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84530 Kernel An app may be able to disclose kernel memory TBDTBD YesYesYesYesNoYesYesYesNoNo
CVE-2026-84544 Kernel Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84549 Kernel Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84558 Kernel An app may be able to cause unexpected system termination TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-84561 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84566 Kernel A local attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesNoNoNoNoNo
CVE-2026-84602 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84622 Kernel An app with root privileges may be able to read uninitialized kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84514 Kext Management An app may be able to modify protected parts of the file system TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84556 Keychain Access An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-65382 LaunchServices An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-86870 libarchive Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesYesYesNoNoNoYesYesNoNo
CVE-2026-84577 libxpc An app may be able to bypass sandbox restrictions TBDTBD NoNoYesYesNoNoNoNoNoNo
CVE-2026-43787 Mail An attacker in a privileged network position may be able to leak sensitive user information TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84573 Mail An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84628 MediaRemote A sandboxed app may be able to access the System Keychain TBDTBD YesNoYesNoNoYesYesYesNoNo
CVE-2026-86924 MobileAccessoryUpdater Connecting a malicious accessory may cause unexpected system termination TBDTBD YesYesYesYesNoNoNoNoNoNo
CVE-2026-65411 MobileBackup An app may be able to modify protected parts of the file system TBDTBD YesYesNoNoNoNoNoYesNoNo
CVE-2026-84598 MobileBackup An attacker with physical access to a trust-paired device may be able to read and write arbitrary files TBDTBD YesYesNoNoNoNoNoNoNoNo
CVE-2026-84497 Model I/O Opening a maliciously crafted file may lead to unexpected process termination TBDTBD YesYesYesYesYesYesNoYesNoNo
CVE-2026-84615 Music An app may be able to access sensitive user data TBDTBD YesYesNoNoNoYesNoYesNoNo
CVE-2026-43695 NetworkExtension An app may be able to access sensitive user data TBDTBD YesNoYesYesYesYesYesYesNoNo
CVE-2026-84585 NetworkExtension An app may be able to access local network devices without user consent TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-84626 NetworkExtension An app may be able to identify what other apps a user has installed TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-86902 NSDocument An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-84629 Photos Storage An app may be able to fingerprint the user TBDTBD YesNoNoNoNoYesYesYesNoNo
CVE-2026-84623 Power Management An app may be able to fingerprint the device TBDTBD YesYesNoNoNoNoNoNoNoNo
CVE-2026-84578 quarantine An app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84580 quarantine An app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84548 Quick Look Processing a maliciously crafted document may lead to an out-of-bounds read TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-28966 RealityKit Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesNoYesNoNo
CVE-2026-84532 RealityKit Opening a maliciously crafted file may cause unexpected process termination or disclose process memory TBDTBD YesYesYesYesYesYesNoYesNoNo
CVE-2026-65403 Reminders An app may be able to access sensitive user data TBDTBD YesYesYesYesYesNoYesYesNoNo
CVE-2026-86897 Safe Browsing An app may be able to access sensitive user data TBDTBD YesYesYesNoNoNoNoYesYesNo
CVE-2026-65380 Sandbox An app may be able to access protected user data TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-84551 Sandbox An app may be able to bypass network restrictions TBDTBD YesNoYesNoNoNoYesYesNoNo
CVE-2026-84603 Sandbox Profiles An app may be able to access sensitive user data TBDTBD YesNoNoNoNoNoYesYesNoNo
CVE-2026-84625 Sandbox Profiles An app may be able to fingerprint the user TBDTBD YesNoYesNoNoNoYesYesNoNo
CVE-2026-43697 SceneKit Processing a maliciously crafted 3D file may lead to an out-of-bounds read TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84526 SceneKit Processing a maliciously crafted 3D scene may lead to unexpected process termination TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84546 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84620 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84531 Security Processing maliciously crafted NTLM input may lead to unexpected app termination TBDTBD YesNoYesNoNoNoNoNoNoNo
CVE-2026-86881 Security An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-84600 Shortcuts A malicious shortcut may be able to send messages without user confirmation TBDTBD YesNoYesNoNoYesYesYesNoNo
CVE-2026-86884 Siri An app may be able to access sensitive user data TBDTBD YesNoYesNoNoYesYesNoNoNo
CVE-2026-86890 Siri Suggestions An attacker with physical access to a locked device may be able to view sensitive user information TBDTBD YesYesNoNoNoNoNoNoNoNo
CVE-2026-65376 SMB An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84509 SMB Connecting to a malicious SMB server may lead to unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84609 Software Update An app may be able to modify protected system files TBDTBD YesNoYesYesYesYesYesYesNoNo
CVE-2026-65361 SoftwareUpdate An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-65378 Spotlight An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84621 Spotlight An app may be able to access sensitive user data TBDTBD YesYesYesYesYesNoNoNoNoNo
CVE-2026-86892 SpringBoard An app may be able to cause a denial-of-service TBDTBD YesYesNoNoNoNoNoYesNoNo
CVE-2026-65345 Storage An app may be able to access user-sensitive data TBDTBD YesYesYesYesYesNoNoNoNoNo
CVE-2026-65348 Storage An app may be able to modify protected parts of the file system TBDTBD YesYesYesYesYesNoNoNoNoNo
CVE-2026-43791 StorageKit An app may be able to read arbitrary files TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-84513 Symptom Framework A malicious application may be able to determine a user's current location TBDTBD YesYesYesYesYesYesYesYesNoNo
CVE-2026-65383 System Settings An app may bypass Gatekeeper checks TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-86909 System Settings An app may be able to bypass Gatekeeper checks TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-84527 TCC An app may be able to access sensitive user data TBDTBD YesNoYesYesYesYesYesYesNoNo
CVE-2026-84589 TCC An app may be able to modify Privacy preferences TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-86886 TCC An app may be able to modify protected system files TBDTBD YesYesNoNoNoNoYesNoNoNo
CVE-2026-65329 Telephony An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic TBDTBD YesNoNoNoNoNoNoNoNoNo
CVE-2026-86887 Time Zone An app may be able to bypass certain Privacy preferences TBDTBD YesYesNoNoNoNoNoYesNoNo
CVE-2026-43696 Touch Bar An app may be able to capture Touch Bar content without authorization TBDTBD NoNoYesNoNoNoNoNoNoNo
CVE-2026-84572 udf An app may be able to cause unexpected system termination or read kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-28899 WebDAV An app may bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo
CVE-2026-65375 WebDAV An app may be able to cause unexpected system termination TBDTBD NoNoYesNoYesNoNoNoNoNo
CVE-2026-84635 WebKit Processing maliciously crafted web content may lead to an unexpected process termination TBDTBD YesNoYesNoNoYesYesYesYesNo
CVE-2026-86898 WebKit Opening a maliciously crafted webarchive file may lead to universal cross-site scripting TBDTBD YesNoYesNoNoNoNoYesYesNo
CVE-2026-84636 Wi-Fi Connectivity An app may be able to access sensitive user data TBDTBD YesNoNoNoNoYesYesYesNoNo
CVE-2026-43674 Wi-Fi3 An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication TBDTBD YesNoNoNoNoNoNoNoNoNo

We’ll continue these macOS updates if people find them useful. Stay tuned for the regularly schedule Patch Tuesday blog covering Adobe and Microsoft.

Hero Background

Stand at the front line of proactive security

TrendAI™ ZDI connects the experts who discover, remediate, and defend.
Add your voice to the work that pushes attackers back.