Apple
iOS 26.7 and iPadOS 26.7
149041 Sep 14, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/149041. 82 CVE entries, 15 additional recognitions. Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/149041
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
170 lines
Showing 101–150 of 170 · page 3 of 4
CVE-2026-84626
BR2026-0000-012705
NetworkExtension
unclaimed
An app may be able to identify what other apps a user has installed
Credited as Hoffcona of IES Red Team
CVE-2026-84623
BR2026-0000-012706
Power Management
unclaimed
An app may be able to fingerprint the device
Credited as Ilya Andr (andrd3v)
CVE-2026-84532
BR2026-0000-012707
RealityKit
unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as Hongsik Kim (mnur)
CVE-2026-84532
BR2026-0000-012708
RealityKit
unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as stratan (@5tratan)
CVE-2026-28966
BR2026-0000-012709
RealityKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-65403
BR2026-0000-012710
Reminders
unclaimed
An app may be able to access sensitive user data
Credited as Rahul Raj
CVE-2026-86897
BR2026-0000-012711
Safe Browsing
unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
CVE-2026-84487
BR2026-0000-012712
SceneKit
unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as stratan (@5tratan)
CVE-2026-84487
BR2026-0000-012713
SceneKit
unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Peter Malone
CVE-2026-84487
BR2026-0000-012714
SceneKit
unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Dhiyanesh Selvaraj (@redroot97)
CVE-2026-84546
BR2026-0000-012715
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Narendra Singh (@_3P1C)
CVE-2026-84546
BR2026-0000-012716
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as stratan (@5tratan)
CVE-2026-84546
BR2026-0000-012717
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84611
BR2026-0000-012718
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84632
BR2026-0000-012719
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84620
BR2026-0000-012720
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84526
BR2026-0000-012721
SceneKit
unclaimed
Processing a maliciously crafted 3D scene may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-86881
BR2026-0000-012722
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Surya Narayan Kushwaha
CVE-2026-86881
BR2026-0000-012723
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Roman Zabicki
CVE-2026-86881
BR2026-0000-012724
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as John Lussier
CVE-2026-86881
BR2026-0000-012725
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Filip Olszak
CVE-2026-86890
BR2026-0000-012726
Siri Suggestions
unclaimed
An attacker with physical access to a locked device may be able to view sensitive user information
Credited as Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India
CVE-2026-84621
BR2026-0000-012727
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Abodi Dawoud
CVE-2026-84621
BR2026-0000-012728
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Ujjwal Reddy Kalvolu Sreenivasa Reddy
CVE-2026-84621
BR2026-0000-012729
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Johan Wahyudi
CVE-2026-84621
BR2026-0000-012730
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Armend Gashi
CVE-2026-86892
BR2026-0000-012731
SpringBoard
unclaimed
An app may be able to cause a denial-of-service
Credited as Lehan Dilusha Jayasingha
CVE-2026-65345
BR2026-0000-012732
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as 이재영
CVE-2026-65345
BR2026-0000-012733
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as Seung Je Seong
CVE-2026-65345
BR2026-0000-012734
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as Jakob Pammer
CVE-2026-65345
BR2026-0000-012735
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as Ilya Andr (andrd3v) of Positive Technologies
CVE-2026-65348
BR2026-0000-012736
Storage
unclaimed
An app may be able to modify protected parts of the file system
Credited as Jérôme Djouder
CVE-2026-84513
BR2026-0000-012737
Symptom Framework
unclaimed
A malicious application may be able to determine a user's current location
Credited as Sindre Sorhus
CVE-2026-86886
BR2026-0000-012738
TCC
unclaimed
An app may be able to modify protected system files
Credited as Constantin Clerc
CVE-2026-86886
BR2026-0000-012739
TCC
unclaimed
An app may be able to modify protected system files
Credited as Shad J
CVE-2026-86886
BR2026-0000-012740
TCC
unclaimed
An app may be able to modify protected system files
Credited as Huy Nguyen (@34306) of Calif.io
CVE-2026-86886
BR2026-0000-012741
TCC
unclaimed
An app may be able to modify protected system files
Credited as huami1314 (@huamidev)
CVE-2026-86904
BR2026-0000-012742
Watch App
unclaimed
An app may be able to track users across apps and websites without permission
Credited as Stanislav Jelezoglo
CVE-2026-43715
BR2026-0000-012743
WebKit
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Milad Nasr
CVE-2026-43715
BR2026-0000-012744
WebKit
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Nicholas Carlini with Claude
CVE-2026-43715
BR2026-0000-012745
WebKit
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Anthropic
CVE-2026-64718
BR2026-0000-012746
WebKit Canvas
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Niels Hofmans
CVE-2026-64718
BR2026-0000-012747
WebKit Canvas
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-84617
BR2026-0000-012748
XPC
unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
Additional recognition
BR2026-0000-012749
AVEVideoEncoder
unclaimed
Credited as tamdao
Additional recognition
BR2026-0000-012750
Bluetooth
unclaimed
Credited as Suresh Sundaram
Additional recognition
BR2026-0000-012751
Contacts
unclaimed
Credited as 이지안 (@speedyfriend433)
Additional recognition
BR2026-0000-012752
Calendar
unclaimed
Credited as Dany Assuid
Additional recognition
BR2026-0000-012753
Calendar
unclaimed
Credited as Jacob Hazak from Zero-Defense Labs
Additional recognition
BR2026-0000-012754
Calendar
unclaimed
Credited as Varik Matevosyan