Apple
macOS Sequoia 15.7.8
128071 Jul 27, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/128071. 138 CVE entries, 13 additional recognitions. Available for: macOS Sequoia. Draft — review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/128071
Are you credited here?
Sign in and claim your line — it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
250 lines
Showing 151–200 of 250 · page 4 of 5
CVE-2026-64721
BR2026-0000-001389
Kernel
unclaimed
An app may be able to access sensitive user data
Credited as Lukas Gerlach
CVE-2026-20672
BR2026-0000-001390
LaunchServices
unclaimed
An app may be able to access sensitive user data
Credited as Kirin (@Pwnrin)
CVE-2026-20672
BR2026-0000-001391
LaunchServices
unclaimed
An app may be able to access sensitive user data
Credited as LFY (@secsys) from Fudan University
CVE-2026-28983
BR2026-0000-001392
LaunchServices
unclaimed
A remote attacker may be able to cause a denial of service
Credited as Ruslan Dautov
CVE-2026-28900
BR2026-0000-001393
libarchive
unclaimed
A maliciously crafted ZIP archive may bypass Gatekeeper checks
Credited as Prathamesh Walunj
CVE-2026-64739
BR2026-0000-001394
Libnotify
unclaimed
An attacker may be able to cause unexpected app termination
Credited as Feng Xue
CVE-2026-64739
BR2026-0000-001395
Libnotify
unclaimed
An attacker may be able to cause unexpected app termination
Credited as XGPT of ThreatBook
CVE-2026-64739
BR2026-0000-001396
Libnotify
unclaimed
An attacker may be able to cause unexpected app termination
Credited as Dun
CVE-2026-43703
BR2026-0000-001397
libxslt
unclaimed
Processing maliciously crafted web content may lead to an unexpected process crash
Credited as Tristan Madani (@TristanInSec) from Talence Security
CVE-2026-43706
BR2026-0000-001398
libxslt
unclaimed
Processing maliciously crafted web content may lead to an unexpected process crash
Credited as Tristan Madani (@TristanInSec) from Talence Security
CVE-2026-43766
BR2026-0000-001399
LoginWindow
unclaimed
An attacker with physical access to a locked device may be able to view sensitive user information
Credited as Amy (amys.website)
CVE-2026-64738
BR2026-0000-001400
Maps
unclaimed
A malicious app may be able to break out of its sandbox
Credited as Robert Mindo
CVE-2026-64738
BR2026-0000-001401
Maps
unclaimed
A malicious app may be able to break out of its sandbox
Credited as Nathaniel Oh (@calysteon)
CVE-2026-43653
BR2026-0000-001402
mDNSResponder
unclaimed
An attacker on the local network may be able to cause a denial-of-service
Credited as Atul R V
CVE-2026-64724
BR2026-0000-001403
mDNSResponder
unclaimed
An attacker on the local network may be able to cause a denial-of-service
Credited as Daisuke Hatakeyama (@SYZD Research)
CVE-2026-43723
BR2026-0000-001404
MediaRemote
unclaimed
An app may be able to gain root privileges
Credited as Richard Zana
CVE-2026-43723
BR2026-0000-001405
MediaRemote
unclaimed
An app may be able to gain root privileges
Credited as Andreas Jaegersberger
CVE-2026-43723
BR2026-0000-001406
MediaRemote
unclaimed
An app may be able to gain root privileges
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-43807
BR2026-0000-001407
MobileAccessoryUpdater
unclaimed
A malicious accessory may be able to cause unexpected app termination
Credited as Tristan Madani (@TristanInSec) from Talence Security
CVE-2026-43733
BR2026-0000-001408
Model I/O
unclaimed
Processing a maliciously crafted image may corrupt process memory
Credited as Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-43729
BR2026-0000-001409
Model I/O
unclaimed
Processing a maliciously crafted image may corrupt process memory
Credited as Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-64772
BR2026-0000-001410
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as wh0am1i
CVE-2026-64772
BR2026-0000-001411
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as stratan (@5tratan)
CVE-2026-64774
BR2026-0000-001412
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as stratan (@5tratan)
CVE-2026-64770
BR2026-0000-001413
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as stratan (@5tratan)
CVE-2026-64769
BR2026-0000-001414
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as stratan (@5tratan)
CVE-2026-64722
BR2026-0000-001415
Model I/O
unclaimed
Processing a 3D model may result in disclosure of process memory
Credited as wh0am1i
CVE-2026-64768
BR2026-0000-001416
Model I/O
unclaimed
A remote attacker may cause an unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-64771
BR2026-0000-001417
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as wh0am1i
CVE-2026-43771
BR2026-0000-001418
Net-SNMP
unclaimed
An app may be able to cause a denial-of-service
Credited as Robert Tran
CVE-2026-43772
BR2026-0000-001419
NetFSFramework
unclaimed
An app may be able to break out of its sandbox
Credited as Mickey Jin (@patch1t)
CVE-2026-28961
BR2026-0000-001420
Network Extensions
unclaimed
An attacker with physical access to a locked device may be able to view sensitive user information
Credited as Dan Raviv
CVE-2026-64711
BR2026-0000-001421
NSColorPanel
unclaimed
An app may be able to leak sensitive user information
Credited as Koh M. Nakagawa (@tsunek0h) of FFRI Security, Inc.
CVE-2026-28912
BR2026-0000-001422
PackageKit
unclaimed
A user may be able to elevate privileges
Credited as Matej Moravec (@MacejkoMoravec)
CVE-2026-43765
BR2026-0000-001423
PackageKit
unclaimed
An app may be able to modify protected parts of the file system
Credited as Mickey Jin (@patch1t)
CVE-2026-28896
BR2026-0000-001424
ppp
unclaimed
An attacker may be able to cause unexpected system termination or read kernel memory
Credited as Dave G.
CVE-2026-64731
BR2026-0000-001425
Printing
unclaimed
A malicious app may be able to break out of its sandbox
Credited as Sindre Sorhus
CVE-2026-64731
BR2026-0000-001426
Printing
unclaimed
A malicious app may be able to break out of its sandbox
Credited as Richard Zana
CVE-2026-43812
BR2026-0000-001427
Pro Res
unclaimed
An app may be able to cause unexpected system termination
Credited as Francisco Knabe
CVE-2026-43694
BR2026-0000-001428
quarantine
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Hcamael
CVE-2026-43694
BR2026-0000-001429
quarantine
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as 章鱼哥@aipy (aipyaipy.com)
CVE-2026-43694
BR2026-0000-001430
quarantine
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as JC Alvarado of Stripe
CVE-2026-43694
BR2026-0000-001431
quarantine
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Jacob Hazak
CVE-2026-39874
BR2026-0000-001432
Remote Management
unclaimed
A malicious app may be able to gain root privileges
Credited as @pixiepointsec
CVE-2026-64764
BR2026-0000-001433
SceneKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Credited as stratan (@5tratan)
CVE-2026-64763
BR2026-0000-001434
SceneKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Credited as stratan (@5tratan)
CVE-2026-64766
BR2026-0000-001435
SceneKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Credited as stratan (@5tratan)
CVE-2026-64765
BR2026-0000-001436
SceneKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Credited as stratan (@5tratan)
CVE-2026-43779
BR2026-0000-001437
Screen Sharing Server
unclaimed
An app may be able to intercept network connections intended for another process
Credited as Dave G.
CVE-2026-43779
BR2026-0000-001438
Screen Sharing Server
unclaimed
An app may be able to intercept network connections intended for another process
Credited as Asaf Cohen