Skip to content
Signals
Monitoring NVD, CISA KEV, EPSS and the Dragons Community ransomware tracker in near-real timeMonitoring NVD, CISA KEV, EPSS and the Dragons Community ransomware tracker in near-real time

Vendors · apple

apple

· 489 Critical

Total CVEs

14,086

Critical

489

Products

195

Search All CVEs →

14,086

Products (195)

macos5,886 CVEsmac os x5,568 CVEsiphone os4,397 CVEstvos2,015 CVEsipados1,901 CVEswatchos1,780 CVEssafari1,611 CVEsitunes922 CVEsmac os x server817 CVEsicloud449 CVEsvisionos435 CVEswebkit258 CVEsquicktime250 CVEsxcode96 CVEsipad os89 CVEsipod touch58 CVEscups56 CVEsapple tv36 CVEsdarwin streaming server27 CVEsiphone23 CVEsquicktime streaming server16 CVEsos x server11 CVEsairport base station firmware11 CVEsswiftnio10 CVEsgarageband9 CVEsairport extreme9 CVEsmusic8 CVEsimageio8 CVEsichat8 CVEsmail7 CVEspages7 CVEstv os7 CVEskeynote7 CVEsapple remote desktop6 CVEsipad6 CVEsairport express6 CVEsswiftnio http\/25 CVEscfnetwork5 CVEsiphoto5 CVEstime capsule4 CVEsnumbers4 CVEsswift4 CVEsafp server4 CVEsiwork4 CVEsterminal4 CVEsipad24 CVEslogic pro x3 CVEsbonjour3 CVEswebcore3 CVEswebobjects3 CVEsmdnsresponder3 CVEsairport express base station firmware3 CVEscoregraphics3 CVEsa ux3 CVEsairport extreme base station firmware3 CVEsical3 CVEspowerpc3 CVEswatch os3 CVEsairport base station3 CVEsmac os runtime for java3 CVEsmac os3 CVEsboot camp2 CVEsairplay audio software development kit2 CVEsairplay video software development kit2 CVEsairpods firmware2 CVEsapple support2 CVEsapplescript2 CVEsappleshare2 CVEscarboncore2 CVEscarplay communication plug-in2 CVEscontainer2 CVEsfiles2 CVEsichat server2 CVEsimovie2 CVEsinstaller2 CVEsinstant message framework2 CVEsjava 1.52 CVEsjava 1.62 CVEsmacbook air2 CVEspersonal web sharing2 CVEsquicktime pictureviewer2 CVEsremote desktop2 CVEsshazam2 CVEsshortcuts2 CVEssoftware update2 CVEsxsan2 CVEscore audio technologies1 CVEscontainerization1 CVEscompressor1 CVEsitunes u1 CVEsclaris emailer1 CVEsjava1 CVEsjava 1.41 CVEsa5x1 CVEsa51 CVEs802.11n1 CVEslibsecurity1 CVEsbomarchivehelper1 CVEsm11 CVEsm1 mac mini1 CVEsm1 max1 CVEsm1 pro1 CVEsm1 ultra1 CVEsm21 CVEsm2 max1 CVEsm2 pro1 CVEsm2 ultra1 CVEsm31 CVEsm3 max1 CVEsm3 pro1 CVEsm3 ultra1 CVEsm41 CVEsm4 max1 CVEsm4 pro1 CVEsbeats fit pro firmware1 CVEsbeats fit pro1 CVEsmac os server1 CVEsappleshare mail server1 CVEsmac os x preview.app1 CVEsapple type services1 CVEsa11 bionic1 CVEsmacbook pro1 CVEsapple music1 CVEsmacos server1 CVEsmagic keyboard1 CVEsmagic keyboard firmware1 CVEsapple laserwriter1 CVEsapple airport extreme base station1 CVEsminimal slp service agent1 CVEsmobile safari1 CVEsmotion1 CVEsapp store connect1 CVEsmusic classical1 CVEsnioextras1 CVEsaperture1 CVEsapache mod digest apple1 CVEsairport utility1 CVEspdfkit1 CVEsweblog server1 CVEspodcast producer1 CVEspowerbeats1 CVEspowerbeats firmware1 CVEsairport card1 CVEspreview1 CVEspro video formats1 CVEspykerberos1 CVEsquartz composer1 CVEsquicklook1 CVEsairpods pro firmware1 CVEsquicktime broadcaster1 CVEsquicktime darwin mp3 broadcaster1 CVEsquicktime mpeg-2 playback component1 CVEsa10x fusion1 CVEsairpods pro1 CVEswindows migration assistant1 CVEsairpods max firmware1 CVEssecurerom1 CVEsserver manager1 CVEsa10 fusion1 CVEsxcode tools1 CVEssmart card services1 CVEsxserve lights-out management1 CVEsstudio display1 CVEsstudio display firmware1 CVEsairpods max1 CVEsswift-crypto1 CVEsswift-nio-extras1 CVEsswift foundation1 CVEsswift prometheus1 CVEsairpods1 CVEsa9x1 CVEsswiftnio ssl1 CVEstcp ip configuration utility1 CVEsa91 CVEstextedit1 CVEstexture1 CVEsa8x1 CVEstokend1 CVEstransporter1 CVEsa81 CVEsa71 CVEsa6x1 CVEsa61 CVEswatch ultra1 CVEswatch ultra 21 CVEsimessage1 CVEsichat av1 CVEsipad mini1 CVEsibooks author1 CVEsexposure notifications1 CVEsdata detectors engine1 CVEsiphone 3gs1 CVEsiphone configuration web utility1 CVEscore image fun house1 CVEsiphone se1 CVEs

Recent Vulnerabilities

View all 14,086
CVE-2026-12033MEDIUM 5.3

Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12027CRITICAL 9.6

Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12025MEDIUM 5.3

Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12024MEDIUM 6.5

Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12023HIGH 8.3

Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12022HIGH 8.3

Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVE-2026-12020HIGH 8.8

Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12017LOW 3.1

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12016HIGH 8.3

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12015MEDIUM 5.3

Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-12014HIGH 8.3

Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

CVE-2026-12012HIGH 8.1

Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

CVE-2026-12009HIGH 8.3

Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-12008HIGH 8.3

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2025-46315HIGH 7.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.

CVE-2025-46313MEDIUM 5.5

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVE-2025-46308MEDIUM 5.3

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.

CVE-2025-46293MEDIUM 5.5

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVE-2025-43339MEDIUM 5.5

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data.

CVE-2025-43278MEDIUM 5.5

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVE-2025-31272HIGH 7.8

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.

CVE-2025-30459MEDIUM 5.5

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVE-2025-30431MEDIUM 5.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

CVE-2025-24284HIGH 8.8

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.

CVE-2025-24268MEDIUM 5.5

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.