Apple
macOS Golden Gate 27
149035 Sep 14, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/149035. 210 CVE entries, 75 additional recognitions. Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020 and later), MacBook Pro with Apple silicon (2020 and later), iMac with Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and later), Mac Studio (2022 and later), and Mac Pro with Apple silicon (2023). Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/149035
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
555 lines
Showing 1–50 of 555 · page 1 of 12
CVE-2026-86882
BR2026-0000-012775
Accelerate Framework
unclaimed
Processing a maliciously crafted image may lead to unexpected process termination
Credited as Peter Malone
CVE-2026-43664
BR2026-0000-012776
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
CVE-2026-43664
BR2026-0000-012777
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Ilya Andr (andrd3v)
CVE-2026-43664
BR2026-0000-012778
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Rosyna Keller of Totally Not Malicious Software
CVE-2026-43664
BR2026-0000-012779
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as CJ Vana
CVE-2026-43664
BR2026-0000-012780
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as David Strnadel
CVE-2026-43664
BR2026-0000-012781
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Daniel Febrero
CVE-2026-43664
BR2026-0000-012782
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Asaf Cohen
CVE-2026-43664
BR2026-0000-012783
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Gongyu Ma (@Mezone0)
CVE-2026-43664
BR2026-0000-012784
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Jian Lee (@speedyfriend433)
CVE-2026-65404
BR2026-0000-012785
Accounts
unclaimed
A malicious application may be able to bypass Privacy preferences
Credited as Arni Hardarson (Neonix Security)
CVE-2026-65404
BR2026-0000-012786
Accounts
unclaimed
A malicious application may be able to bypass Privacy preferences
Credited as Vinay Kumar Rasala (Xplo8E) from Appknox
CVE-2026-65404
BR2026-0000-012787
Accounts
unclaimed
A malicious application may be able to bypass Privacy preferences
Credited as Stuart Wallace
CVE-2026-65404
BR2026-0000-012788
Accounts
unclaimed
A malicious application may be able to bypass Privacy preferences
Credited as 이재영
CVE-2026-84523
BR2026-0000-012789
APFS
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Cem Onat Karagun
CVE-2026-86888
BR2026-0000-012790
App Store
unclaimed
A local app may be able to read a persistent account identifier
Credited as Zhongcheng Li (CK01)
CVE-2026-84586
BR2026-0000-012791
Apple Account
unclaimed
A malicious application may be able to leak sensitive user information
Credited as Prashan Samarathunge
CVE-2026-84586
BR2026-0000-012792
Apple Account
unclaimed
A malicious application may be able to leak sensitive user information
Credited as Zhongcheng Li (CK01)
CVE-2026-20683
BR2026-0000-012793
Apple Account
unclaimed
An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account
Credited as Dem0ns (@天府简易信工作室)
CVE-2026-20683
BR2026-0000-012794
Apple Account
unclaimed
An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account
Credited as Abdelhak Kherroubi
CVE-2026-20683
BR2026-0000-012795
Apple Account
unclaimed
An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account
Credited as Jasminder Pal Singh
CVE-2026-20683
BR2026-0000-012796
Apple Account
unclaimed
An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account
Credited as Lehan Dilusha Jayasingha (Sri Lanka)
CVE-2026-84601
BR2026-0000-012797
Apple Intelligence
unclaimed
An app may be able to bypass Apple Intelligence security prompts
Credited as Nick Cook
CVE-2026-84601
BR2026-0000-012798
Apple Intelligence
unclaimed
An app may be able to bypass Apple Intelligence security prompts
Credited as Sentry Flag
CVE-2026-65408
BR2026-0000-012799
Apple Neural Engine
unclaimed
An app may be able to cause unexpected system termination
Credited as tamdao
CVE-2026-65407
BR2026-0000-012800
AppleAVD
unclaimed
An app may be able to cause unexpected system termination
Credited as Franco Belman at Blackwing Intelligence
CVE-2026-84519
BR2026-0000-012801
AppleDouble
unclaimed
Mounting a disk image with maliciously crafted files may lead to unexpected system termination
Credited as Richard Zana
CVE-2026-84520
BR2026-0000-012802
AppleFDEKeyStore
unclaimed
A local attacker may be able to cause unexpected system termination or corrupt kernel memory
Credited as Billy Jheng Bing Jhong
CVE-2026-84520
BR2026-0000-012803
AppleFDEKeyStore
unclaimed
A local attacker may be able to cause unexpected system termination or corrupt kernel memory
Credited as Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-65381
BR2026-0000-012804
AppleMobileFileIntegrity
unclaimed
A malicious app may be able to break out of its sandbox
Credited as Mickey Jin (@patch1t)
CVE-2026-84584
BR2026-0000-012805
Archive Utility
unclaimed
An app may be able to break out of its sandbox
Credited as Mickey Jin (@patch1t)
CVE-2026-84522
BR2026-0000-012806
Archive Utility
unclaimed
An app may be able to access sensitive user data
Credited as Mickey Jin (@patch1t)
CVE-2026-84525
BR2026-0000-012807
ATS
unclaimed
An app may be able to access user-sensitive data
Credited as D4rthL
CVE-2026-65342
BR2026-0000-012808
ATS
unclaimed
An app may be able to access sensitive user data
Credited as Ahmed Alwardani
CVE-2026-65342
BR2026-0000-012809
ATS
unclaimed
An app may be able to access sensitive user data
Credited as Mohamad Dawoud / Abodi Dawoud
CVE-2026-86905
BR2026-0000-012810
Authentication Services
unclaimed
An app may be able to delete credentials stored in Keychain
Credited as Ilya Andr (andrd3v)
CVE-2026-84583
BR2026-0000-012811
AuthKit
unclaimed
A local app may be able to read a persistent account identifier
Credited as Zhongcheng Li from IES Red Team
CVE-2026-84570
BR2026-0000-012812
autofs
unclaimed
An app may be able to bypass Gatekeeper checks
Credited as Mr.Gedik (@h4ck2s3c)
CVE-2026-84568
BR2026-0000-012813
autofs
unclaimed
An attacker with control of a network directory server may be able to execute arbitrary code with root privileges
Credited as Mr.Gedik (@h4ck2s3c) of Turkish Technology
CVE-2026-84535
BR2026-0000-012814
Automator
unclaimed
An app may be able to break out of its sandbox
Credited as Kun Peeks (@SwayZGl1tZyyy)
CVE-2026-84535
BR2026-0000-012815
Automator
unclaimed
An app may be able to break out of its sandbox
Credited as Oren Yomtov
CVE-2026-84535
BR2026-0000-012816
Automator
unclaimed
An app may be able to break out of its sandbox
Credited as Morris Richman (@morrisinlife)
CVE-2026-84535
BR2026-0000-012817
Automator
unclaimed
An app may be able to break out of its sandbox
Credited as Sindre Sorhus
CVE-2026-65410
BR2026-0000-012818
AVEVideoEncoder
unclaimed
An app may be able to cause unexpected system termination
Credited as Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84616
BR2026-0000-012819
AVEVideoEncoder
unclaimed
An app may be able to cause unexpected system termination
Credited as Peter Malone
CVE-2026-84607
BR2026-0000-012820
AVEVideoEncoder
unclaimed
A sandboxed app may be able to execute arbitrary code with kernel privileges
Credited as Ruslan Dautov
CVE-2026-65406
BR2026-0000-012821
BackgroundAssets
unclaimed
An app may be able to access sensitive user data
Credited as Ye Zhang (@VAR10CK) of Baidu Security
CVE-2026-84631
BR2026-0000-012822
Bluetooth
unclaimed
An app may be able to gain root privileges
Credited as Andreas Jaegersberger
CVE-2026-84631
BR2026-0000-012823
Bluetooth
unclaimed
An app may be able to gain root privileges
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-84567
BR2026-0000-012824
cd9660
unclaimed
An app may be able to cause unexpected system termination
Credited as Sanny Mitra