Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Apple

iOS 18.7.9 and iPadOS 18.7.9

127111 May 11, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/127111. 47 CVE entries, 5 additional recognitions. Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/127111
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

76 lines
Showing 1–50 of 71 matching · page 1 of 2 · clear filters
CVE-2026-28877 BR2026-0000-007185 Accounts unclaimed
An app may be able to access sensitive user data
Credited as Rosyna Keller of Totally Not Malicious Software
CVE-2026-28959 BR2026-0000-007186 APFS unclaimed
An app may be able to cause unexpected system termination
Credited as Dave G.
CVE-2026-28995 BR2026-0000-007187 App Intents unclaimed
A malicious app may be able to break out of its sandbox
Credited as Vamshi Paili
CVE-2026-28995 BR2026-0000-007188 App Intents unclaimed
A malicious app may be able to break out of its sandbox
Credited as Tony Gorez (@tonygo_) for Reverse Society
CVE-2026-39869 BR2026-0000-007189 Audio unclaimed
Processing an audio stream in a maliciously crafted media file may terminate the process
Credited as David Ige of Beryllium Security
CVE-2026-28872 BR2026-0000-007190 Calendar unclaimed
A remote attacker may be able to cause a denial-of-service
Credited as Alvin Aries Tapia
CVE-2026-28936 BR2026-0000-007191 CoreServices unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as Andreas Jaegersberger
CVE-2026-28936 BR2026-0000-007192 CoreServices unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-43659 BR2026-0000-007193 FileProvider unclaimed
An app may be able to access sensitive user data
Credited as Alex Radocea
CVE-2026-28870 BR2026-0000-007194 GeoServices unclaimed
An app may be able to access sensitive user data
Credited as XiguaSec
CVE-2026-28977 BR2026-0000-007195 ImageIO unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as Suresh Sundaram
CVE-2026-28992 BR2026-0000-007196 IOHIDFamily unclaimed
An attacker may be able to cause unexpected app termination
Credited as Johnny Franks (@zeroxjf)
CVE-2026-28943 BR2026-0000-007197 IOHIDFamily unclaimed
An app may be able to determine kernel memory layout
Credited as Google Threat Analysis Group
CVE-2026-28969 BR2026-0000-007198 IOKit unclaimed
An app may be able to cause unexpected system termination
Credited as Mihalis Haatainen
CVE-2026-28969 BR2026-0000-007199 IOKit unclaimed
An app may be able to cause unexpected system termination
Credited as Ari Hawking
CVE-2026-28969 BR2026-0000-007200 IOKit unclaimed
An app may be able to cause unexpected system termination
Credited as Ashish Kunwar
CVE-2026-43654 BR2026-0000-007201 Kernel unclaimed
An app may be able to disclose kernel memory
Credited as Vaagn Vardanian
CVE-2026-43654 BR2026-0000-007202 Kernel unclaimed
An app may be able to disclose kernel memory
Credited as Nathaniel Oh (@calysteon)
CVE-2026-28954 BR2026-0000-007203 Kernel unclaimed
A maliciously crafted disk image may bypass Gatekeeper checks
Credited as Yiğit Can YILMAZ (@yilmazcanyigit)
CVE-2026-28897 BR2026-0000-007204 Kernel unclaimed
A local user may be able to cause unexpected system termination or read kernel memory
Credited as Robert Tran
CVE-2026-28897 BR2026-0000-007205 Kernel unclaimed
A local user may be able to cause unexpected system termination or read kernel memory
Credited as popku1337
CVE-2026-28897 BR2026-0000-007206 Kernel unclaimed
A local user may be able to cause unexpected system termination or read kernel memory
Credited as Billy Jheng Bing Jhong
CVE-2026-28897 BR2026-0000-007207 Kernel unclaimed
A local user may be able to cause unexpected system termination or read kernel memory
Credited as Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-28897 BR2026-0000-007208 Kernel unclaimed
A local user may be able to cause unexpected system termination or read kernel memory
Credited as Aswin kumar Gokulakannan
CVE-2026-28952 BR2026-0000-007209 Kernel unclaimed
An app may be able to cause unexpected system termination
Credited as Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-28951 BR2026-0000-007210 Kernel unclaimed
An app may be able to gain root privileges
Credited as Csaba Fitzl (@theevilbit) of Iru
CVE-2026-28972 BR2026-0000-007211 Kernel unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Billy Jheng Bing Jhong
CVE-2026-28972 BR2026-0000-007212 Kernel unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-28972 BR2026-0000-007213 Kernel unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Ryan Hileman via Xint Code (xint.io)
CVE-2026-28986 BR2026-0000-007214 Kernel unclaimed
An app may be able to cause unexpected system termination
Credited as Tristan Madani (@TristanInSec) from Talence Security
CVE-2026-28986 BR2026-0000-007215 Kernel unclaimed
An app may be able to cause unexpected system termination
Credited as Ryan Hileman via Xint Code (xint.io)
CVE-2026-28986 BR2026-0000-007216 Kernel unclaimed
An app may be able to cause unexpected system termination
Credited as Chris Betz
CVE-2026-28987 BR2026-0000-007217 Kernel unclaimed
An app may be able to leak sensitive kernel state
Credited as Dhiyanesh Selvaraj (@redroot97)
CVE-2026-28983 BR2026-0000-007218 LaunchServices unclaimed
A remote attacker may be able to cause a denial of service
Credited as Ruslan Dautov
CVE-2026-28882 BR2026-0000-007219 libxpc unclaimed
An app may be able to enumerate a user's installed apps
Credited as Ilya Andr (andrd3v)
CVE-2026-28882 BR2026-0000-007220 libxpc unclaimed
An app may be able to enumerate a user's installed apps
Credited as Ilias Morad (A2nkF) of Voynich Group
CVE-2026-28882 BR2026-0000-007221 libxpc unclaimed
An app may be able to enumerate a user's installed apps
Credited as Duy Trần (@khanhduytran0)
CVE-2026-28882 BR2026-0000-007222 libxpc unclaimed
An app may be able to enumerate a user's installed apps
Credited as @hugeBlack
CVE-2026-28929 BR2026-0000-007223 Mail Drafts unclaimed
Replying to an email could display remote images in Mail in Lockdown Mode
Credited as Yiğit Can YILMAZ (@yilmazcanyigit)
CVE-2026-43653 BR2026-0000-007224 mDNSResponder unclaimed
An attacker on the local network may be able to cause a denial-of-service
Credited as Atul R V
CVE-2026-43668 BR2026-0000-007225 mDNSResponder unclaimed
A remote attacker may be able to cause unexpected system termination or corrupt kernel memory
Credited as Ricardo Prado
CVE-2026-43668 BR2026-0000-007226 mDNSResponder unclaimed
A remote attacker may be able to cause unexpected system termination or corrupt kernel memory
Credited as Anton Pakhunov
CVE-2026-43666 BR2026-0000-007227 mDNSResponder unclaimed
An attacker on the local network may be able to cause a denial-of-service
Credited as Ian van der Wurff (ian.nl)
CVE-2026-28940 BR2026-0000-007228 Model I/O unclaimed
Processing a maliciously crafted image may corrupt process memory
Credited as Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-28941 BR2026-0000-007229 Model I/O unclaimed
Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents
Credited as Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-28906 BR2026-0000-007230 Networking unclaimed
An attacker may be able to track users through their IP address
Credited as Ilya Sc. Jowell A.
CVE-2026-28873 BR2026-0000-007231 Privacy unclaimed
An app may be able to circumvent App Privacy Report logging
Credited as Guy Dor
CVE-2026-43656 BR2026-0000-007232 Quick Look unclaimed
Parsing a maliciously crafted file may lead to an unexpected app termination
Credited as Peter Malone
CVE-2026-28846 BR2026-0000-007233 SceneKit unclaimed
A remote attacker may be able to cause unexpected app termination
Credited as Peter Malone
CVE-2026-28993 BR2026-0000-007234 Shortcuts unclaimed
An app may be able to access user-sensitive data
Credited as Doron Assness