Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Apple

iOS 26.7 and iPadOS 26.7

149041 Sep 14, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/149041. 82 CVE entries, 15 additional recognitions. Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/149041
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

170 lines
Showing 101–150 of 170 · page 3 of 4
CVE-2026-84626 BR2026-0000-012705 NetworkExtension unclaimed
An app may be able to identify what other apps a user has installed
Credited as Hoffcona of IES Red Team
CVE-2026-84623 BR2026-0000-012706 Power Management unclaimed
An app may be able to fingerprint the device
Credited as Ilya Andr (andrd3v)
CVE-2026-84532 BR2026-0000-012707 RealityKit unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as Hongsik Kim (mnur)
CVE-2026-84532 BR2026-0000-012708 RealityKit unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as stratan (@5tratan)
CVE-2026-28966 BR2026-0000-012709 RealityKit unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-65403 BR2026-0000-012710 Reminders unclaimed
An app may be able to access sensitive user data
Credited as Rahul Raj
CVE-2026-86897 BR2026-0000-012711 Safe Browsing unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
CVE-2026-84487 BR2026-0000-012712 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as stratan (@5tratan)
CVE-2026-84487 BR2026-0000-012713 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Peter Malone
CVE-2026-84487 BR2026-0000-012714 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Dhiyanesh Selvaraj (@redroot97)
CVE-2026-84546 BR2026-0000-012715 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Narendra Singh (@_3P1C)
CVE-2026-84546 BR2026-0000-012716 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as stratan (@5tratan)
CVE-2026-84546 BR2026-0000-012717 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84611 BR2026-0000-012718 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84632 BR2026-0000-012719 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84620 BR2026-0000-012720 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84526 BR2026-0000-012721 SceneKit unclaimed
Processing a maliciously crafted 3D scene may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-86881 BR2026-0000-012722 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Surya Narayan Kushwaha
CVE-2026-86881 BR2026-0000-012723 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Roman Zabicki
CVE-2026-86881 BR2026-0000-012724 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as John Lussier
CVE-2026-86881 BR2026-0000-012725 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Filip Olszak
CVE-2026-86890 BR2026-0000-012726 Siri Suggestions unclaimed
An attacker with physical access to a locked device may be able to view sensitive user information
Credited as Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India
CVE-2026-84621 BR2026-0000-012727 Spotlight unclaimed
An app may be able to access sensitive user data
Credited as Abodi Dawoud
CVE-2026-84621 BR2026-0000-012728 Spotlight unclaimed
An app may be able to access sensitive user data
Credited as Ujjwal Reddy Kalvolu Sreenivasa Reddy
CVE-2026-84621 BR2026-0000-012729 Spotlight unclaimed
An app may be able to access sensitive user data
Credited as Johan Wahyudi
CVE-2026-84621 BR2026-0000-012730 Spotlight unclaimed
An app may be able to access sensitive user data
Credited as Armend Gashi
CVE-2026-86892 BR2026-0000-012731 SpringBoard unclaimed
An app may be able to cause a denial-of-service
Credited as Lehan Dilusha Jayasingha
CVE-2026-65345 BR2026-0000-012732 Storage unclaimed
An app may be able to access user-sensitive data
Credited as 이재영
CVE-2026-65345 BR2026-0000-012733 Storage unclaimed
An app may be able to access user-sensitive data
Credited as Seung Je Seong
CVE-2026-65345 BR2026-0000-012734 Storage unclaimed
An app may be able to access user-sensitive data
Credited as Jakob Pammer
CVE-2026-65345 BR2026-0000-012735 Storage unclaimed
An app may be able to access user-sensitive data
Credited as Ilya Andr (andrd3v) of Positive Technologies
CVE-2026-65348 BR2026-0000-012736 Storage unclaimed
An app may be able to modify protected parts of the file system
Credited as Jérôme Djouder
CVE-2026-84513 BR2026-0000-012737 Symptom Framework unclaimed
A malicious application may be able to determine a user's current location
Credited as Sindre Sorhus
CVE-2026-86886 BR2026-0000-012738 TCC unclaimed
An app may be able to modify protected system files
Credited as Constantin Clerc
CVE-2026-86886 BR2026-0000-012739 TCC unclaimed
An app may be able to modify protected system files
Credited as Shad J
CVE-2026-86886 BR2026-0000-012740 TCC unclaimed
An app may be able to modify protected system files
Credited as Huy Nguyen (@34306) of Calif.io
CVE-2026-86886 BR2026-0000-012741 TCC unclaimed
An app may be able to modify protected system files
Credited as huami1314 (@huamidev)
CVE-2026-86904 BR2026-0000-012742 Watch App unclaimed
An app may be able to track users across apps and websites without permission
Credited as Stanislav Jelezoglo
CVE-2026-43715 BR2026-0000-012743 WebKit unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Milad Nasr
CVE-2026-43715 BR2026-0000-012744 WebKit unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Nicholas Carlini with Claude
CVE-2026-43715 BR2026-0000-012745 WebKit unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Anthropic
CVE-2026-64718 BR2026-0000-012746 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Niels Hofmans
CVE-2026-64718 BR2026-0000-012747 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-84617 BR2026-0000-012748 XPC unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
Additional recognition BR2026-0000-012749 AVEVideoEncoder unclaimed
Credited as tamdao
Additional recognition BR2026-0000-012750 Bluetooth unclaimed
Credited as Suresh Sundaram
Additional recognition BR2026-0000-012751 Contacts unclaimed
Credited as 이지안 (@speedyfriend433)
Additional recognition BR2026-0000-012752 Calendar unclaimed
Credited as Dany Assuid
Additional recognition BR2026-0000-012753 Calendar unclaimed
Credited as Jacob Hazak from Zero-Defense Labs
Additional recognition BR2026-0000-012754 Calendar unclaimed
Credited as Varik Matevosyan