Apple
macOS Tahoe 26.7
149042 Sep 14, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/149042. 154 CVE entries, 12 additional recognitions. Available for: macOS Tahoe. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/149042
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
315 lines
Showing 51–100 of 315 · page 2 of 7
CVE-2026-65344
BR2026-0000-013419
CoreMedia
unclaimed
Processing a maliciously crafted video file may lead to unexpected app termination
Credited as Siyeong kim
CVE-2026-86876
BR2026-0000-013420
CoreMedia
unclaimed
A sandboxed process may be able to circumvent sandbox restrictions
Credited as Chris Bailey - Short Circuit
CVE-2026-43702
BR2026-0000-013421
CoreMedia Video Toolbox
unclaimed
Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84624
BR2026-0000-013422
CoreML
unclaimed
A sandboxed app may be able to access restricted files
Credited as AL Najafi
CVE-2026-84624
BR2026-0000-013423
CoreML
unclaimed
A sandboxed app may be able to access restricted files
Credited as tamdao
CVE-2026-43737
BR2026-0000-013424
CoreMotion
unclaimed
An app may be able to access motion data from headphones without user consent
Credited as Stuart Wallace
CVE-2026-84574
BR2026-0000-013425
CoreServices
unclaimed
An app may be able to bypass Privacy preferences
Credited as Mickey Jin (@patch1t)
CVE-2026-28899
BR2026-0000-013426
CoreServices
unclaimed
An app may bypass Gatekeeper checks
Credited as Kraken Cryptocurrency Exchange
CVE-2026-28899
BR2026-0000-013427
CoreServices
unclaimed
An app may bypass Gatekeeper checks
Credited as Andreas Jaegersberger
CVE-2026-28899
BR2026-0000-013428
CoreServices
unclaimed
An app may bypass Gatekeeper checks
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-84559
BR2026-0000-013429
CoreServices
unclaimed
A malicious application may be able to access restricted files
Credited as Ryan Hughes
CVE-2026-43786
BR2026-0000-013430
CoreServices
unclaimed
An app may be able to gain root privileges
Credited as Kujtim Kryeziu (Sentry)
CVE-2026-65412
BR2026-0000-013431
CoreText
unclaimed
Processing web content may lead to a denial-of-service
Credited as Pavan Nallamothu
CVE-2026-84575
BR2026-0000-013432
CoreUI
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as Mustafa Calap (@ordinal0, dbg.re)
CVE-2026-84511
BR2026-0000-013433
CoreUI
unclaimed
Processing a maliciously crafted asset catalog may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-84511
BR2026-0000-013434
CoreUI
unclaimed
Processing a maliciously crafted asset catalog may lead to unexpected process termination
Credited as Rahul Raj
CVE-2026-84563
BR2026-0000-013435
CUPS
unclaimed
An app may be able to cause unexpected system termination
Credited as Yongyue WANG AKA Brian.W of OKX security
CVE-2026-84563
BR2026-0000-013436
CUPS
unclaimed
An app may be able to cause unexpected system termination
Credited as Omar Cerrito
CVE-2026-64790
BR2026-0000-013437
CUPS
unclaimed
An app may be able to gain elevated privileges
Credited as Aaron Grattafiori - NVIDIA AI Red Team
CVE-2026-43692
BR2026-0000-013438
CUPS
unclaimed
A remote user may cause an unexpected app termination or arbitrary code execution
Credited as Aaron Grattafiori - NVIDIA AI Red Team
CVE-2026-84554
BR2026-0000-013439
CUPS
unclaimed
An attacker in a privileged network position may be able to cause a denial-of-service
Credited as Meshaal @ Darkcov
CVE-2026-84554
BR2026-0000-013440
CUPS
unclaimed
An attacker in a privileged network position may be able to cause a denial-of-service
Credited as Joseph Shamoon
CVE-2026-84540
BR2026-0000-013441
CUPS
unclaimed
An app may be able to access sensitive user data
Credited as Yongyue WANG AKA Brian.W of OKX security
CVE-2026-84540
BR2026-0000-013442
CUPS
unclaimed
An app may be able to access sensitive user data
Credited as 章鱼哥@aipy (aipyaipy.com)
CVE-2026-84540
BR2026-0000-013443
CUPS
unclaimed
An app may be able to access sensitive user data
Credited as instantraaamen (github.com/instantraaamen) Contact: masa.shiramizu@gmail.com
CVE-2026-43691
BR2026-0000-013444
CUPS
unclaimed
An app may be able to gain root privileges
Credited as Andreas Jaegersberger
CVE-2026-43691
BR2026-0000-013445
CUPS
unclaimed
An app may be able to gain root privileges
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-84516
BR2026-0000-013446
CUPS
unclaimed
Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory
Credited as 章鱼哥@aipy (aipyaipy.com)
CVE-2026-43698
BR2026-0000-013447
CUPS
unclaimed
An app may be able to gain root privileges
Credited as Andreas Jaegersberger
CVE-2026-43698
BR2026-0000-013448
CUPS
unclaimed
An app may be able to gain root privileges
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-84541
BR2026-0000-013449
CUPS
unclaimed
An application may be able to access restricted files
Credited as 章鱼哥@aipy (aipyaipy.com)
CVE-2026-84612
BR2026-0000-013450
DeviceCheck
unclaimed
An app may be able to read persistent device identifiers
Credited as N.M.Praveen Nawarathne (@zblockrat)
CVE-2026-84612
BR2026-0000-013451
DeviceCheck
unclaimed
An app may be able to read persistent device identifiers
Credited as James Gill (@jjtech@infosec.exchange)
CVE-2026-84505
BR2026-0000-013452
Directory Utility
unclaimed
An app may be able to gain root privileges
Credited as Tommy DeVoss from Braze Security Team (@thedawgyg)
CVE-2026-84552
BR2026-0000-013453
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as Tommy DeVoss from Braze Security Team (@thedawgyg)
CVE-2026-84552
BR2026-0000-013454
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as PETOWORKS의 Bugeun Choi (@Bugeun)
CVE-2026-84552
BR2026-0000-013455
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as Peter Malone
CVE-2026-84552
BR2026-0000-013456
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as Hyunwoo Kim (@v4bel)
CVE-2026-84552
BR2026-0000-013457
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as flower xu
CVE-2026-84552
BR2026-0000-013458
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as Daisuke Hatakeyama
CVE-2026-84552
BR2026-0000-013459
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as Ryohei Ueki (@SYZD Research)
CVE-2026-84552
BR2026-0000-013460
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as Adriatik Raci
CVE-2026-84565
BR2026-0000-013461
Disk Images
unclaimed
Processing a maliciously crafted disk image may lead to unexpected app termination
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84550
BR2026-0000-013462
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as Hyunwoo Kim (@v4bel)
CVE-2026-84550
BR2026-0000-013463
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as Daisuke Hatakeyama
CVE-2026-84550
BR2026-0000-013464
Disk Images
unclaimed
An app may be able to cause unexpected system termination
Credited as Ryohei Ueki (@SYZD Research)
CVE-2026-65362
BR2026-0000-013465
Disk Images
unclaimed
An app may be able to gain root privileges
Credited as Manish Bhatt
CVE-2026-65362
BR2026-0000-013466
Disk Images
unclaimed
An app may be able to gain root privileges
Credited as Amazon Leo Security
CVE-2026-65362
BR2026-0000-013467
Disk Images
unclaimed
An app may be able to gain root privileges
Credited as Nathaniel Oh (@calysteon)
CVE-2026-65362
BR2026-0000-013468
Disk Images
unclaimed
An app may be able to gain root privileges
Credited as Andreas Jaegersberger