Apple
macOS Tahoe 26.6
128067 Jul 27, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/128067. 153 CVE entries, 26 additional recognitions. Available for: macOS Tahoe. Draft — review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/128067
Are you credited here?
Sign in and claim your line — it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
376 lines
Showing 201–250 of 376 · page 5 of 8
CVE-2026-64720
BR2026-0000-001063
Kernel
unclaimed
An app may be able to cause unexpected system termination
Credited as Ye Zhang
CVE-2026-43754
BR2026-0000-001064
Kernel
unclaimed
An app may be able to leak sensitive kernel state
Credited as Calif Research
CVE-2026-43754
BR2026-0000-001065
Kernel
unclaimed
An app may be able to leak sensitive kernel state
Credited as Ernesto Martínez García
CVE-2026-64751
BR2026-0000-001066
Kernel
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as N.M.Praveen Nawarathne (@zblockrat)
CVE-2026-64721
BR2026-0000-001067
Kernel
unclaimed
An app may be able to access sensitive user data
Credited as Lukas Gerlach
CVE-2026-64739
BR2026-0000-001068
Libnotify
unclaimed
An attacker may be able to cause unexpected app termination
Credited as Feng Xue
CVE-2026-64739
BR2026-0000-001069
Libnotify
unclaimed
An attacker may be able to cause unexpected app termination
Credited as XGPT of ThreatBook
CVE-2026-64739
BR2026-0000-001070
Libnotify
unclaimed
An attacker may be able to cause unexpected app termination
Credited as Dun
CVE-2026-43766
BR2026-0000-001071
LoginWindow
unclaimed
An attacker with physical access to a locked device may be able to view sensitive user information
Credited as Amy (amys.website)
CVE-2026-64743
BR2026-0000-001072
Managed Configuration
unclaimed
An app may be able to access sensitive user data
Credited as Daniel Febrero
CVE-2026-64738
BR2026-0000-001073
Maps
unclaimed
A malicious app may be able to break out of its sandbox
Credited as Nathaniel Oh (@calysteon)
CVE-2026-64738
BR2026-0000-001074
Maps
unclaimed
A malicious app may be able to break out of its sandbox
Credited as Robert Mindo
CVE-2026-43806
BR2026-0000-001075
mDNSResponder
unclaimed
A local attacker may be able to cause a denial of service
Credited as He Wei (ギカク)
CVE-2026-43806
BR2026-0000-001076
mDNSResponder
unclaimed
A local attacker may be able to cause a denial of service
Credited as 章鱼哥 (@aipy) of aipyaipy.com
CVE-2026-43806
BR2026-0000-001077
mDNSResponder
unclaimed
A local attacker may be able to cause a denial of service
Credited as Jex Amro
CVE-2026-43806
BR2026-0000-001078
mDNSResponder
unclaimed
A local attacker may be able to cause a denial of service
Credited as Cem Onat Karagun
CVE-2026-64724
BR2026-0000-001079
mDNSResponder
unclaimed
An attacker on the local network may be able to cause a denial-of-service
Credited as Daisuke Hatakeyama (@SYZD Research)
CVE-2026-43723
BR2026-0000-001080
MediaRemote
unclaimed
An app may be able to gain root privileges
Credited as Richard Zana
CVE-2026-43723
BR2026-0000-001081
MediaRemote
unclaimed
An app may be able to gain root privileges
Credited as Andreas Jaegersberger
CVE-2026-43723
BR2026-0000-001082
MediaRemote
unclaimed
An app may be able to gain root privileges
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-28911
BR2026-0000-001083
Metal
unclaimed
A malicious app may be able to corrupt memory of a system process
Credited as yk lin of @pixiepointsec
CVE-2026-43733
BR2026-0000-001084
Model I/O
unclaimed
Processing a maliciously crafted image may corrupt process memory
Credited as Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-43729
BR2026-0000-001085
Model I/O
unclaimed
Processing a maliciously crafted image may corrupt process memory
Credited as Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-64772
BR2026-0000-001086
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as stratan (@5tratan)
CVE-2026-64772
BR2026-0000-001087
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as wh0am1i
CVE-2026-64771
BR2026-0000-001088
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as wh0am1i
CVE-2026-64722
BR2026-0000-001089
Model I/O
unclaimed
Processing a 3D model may result in disclosure of process memory
Credited as wh0am1i
CVE-2026-64774
BR2026-0000-001090
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as stratan (@5tratan)
CVE-2026-64770
BR2026-0000-001091
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as stratan (@5tratan)
CVE-2026-64769
BR2026-0000-001092
Model I/O
unclaimed
A remote attacker may be able to cause unexpected application termination or heap corruption
Credited as stratan (@5tratan)
CVE-2026-64768
BR2026-0000-001093
Model I/O
unclaimed
A remote attacker may cause an unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-43771
BR2026-0000-001094
Net-SNMP
unclaimed
An app may be able to cause a denial-of-service
Credited as Robert Tran
CVE-2026-43772
BR2026-0000-001095
NetFSFramework
unclaimed
An app may be able to break out of its sandbox
Credited as Mickey Jin (@patch1t)
CVE-2026-64711
BR2026-0000-001096
NSColorPanel
unclaimed
An app may be able to leak sensitive user information
Credited as Koh M. Nakagawa (@tsunek0h) of FFRI Security, Inc.
CVE-2026-28912
BR2026-0000-001097
PackageKit
unclaimed
A user may be able to elevate privileges
Credited as Matej Moravec (@MacejkoMoravec)
CVE-2026-43765
BR2026-0000-001098
PackageKit
unclaimed
An app may be able to modify protected parts of the file system
Credited as Mickey Jin (@patch1t)
CVE-2026-64731
BR2026-0000-001099
Printing
unclaimed
A malicious app may be able to break out of its sandbox
Credited as Sindre Sorhus
CVE-2026-64731
BR2026-0000-001100
Printing
unclaimed
A malicious app may be able to break out of its sandbox
Credited as Richard Zana
CVE-2026-43812
BR2026-0000-001101
Pro Res
unclaimed
An app may be able to cause unexpected system termination
Credited as Francisco Knabe
CVE-2026-43694
BR2026-0000-001102
quarantine
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Hcamael
CVE-2026-43694
BR2026-0000-001103
quarantine
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as 章鱼哥@aipy (aipyaipy.com)
CVE-2026-43694
BR2026-0000-001104
quarantine
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as JC Alvarado of Stripe
CVE-2026-43694
BR2026-0000-001105
quarantine
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Jacob Hazak
CVE-2026-39874
BR2026-0000-001106
Remote Management
unclaimed
A malicious app may be able to gain root privileges
Credited as @pixiepointsec
CVE-2026-43792
BR2026-0000-001107
Safari
unclaimed
An app may be able to access sensitive user data
Credited as Ilya Andr (andrd3v)
CVE-2026-64766
BR2026-0000-001108
SceneKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Credited as stratan (@5tratan)
CVE-2026-64765
BR2026-0000-001109
SceneKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Credited as stratan (@5tratan)
CVE-2026-64764
BR2026-0000-001110
SceneKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Credited as stratan (@5tratan)
CVE-2026-64763
BR2026-0000-001111
SceneKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Credited as stratan (@5tratan)
CVE-2026-43779
BR2026-0000-001112
Screen Sharing Server
unclaimed
An app may be able to intercept network connections intended for another process
Credited as Dave G.