Filtered by vendor Apple
Subscribe
Total
15313 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-21271 | 3 Adobe, Apple, Microsoft | 3 Dreamweaver, Macos, Windows | 2026-08-28 | N/A | 8.6 HIGH |
| Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed. | |||||
| CVE-2026-21268 | 3 Adobe, Apple, Microsoft | 3 Dreamweaver, Macos, Windows | 2026-08-28 | N/A | 8.6 HIGH |
| Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed. | |||||
| CVE-2026-21267 | 3 Adobe, Apple, Microsoft | 3 Dreamweaver, Macos, Windows | 2026-08-28 | N/A | 8.6 HIGH |
| Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed. | |||||
| CVE-2026-64777 | 1 Apple | 1 Container | 2026-08-27 | N/A | 4.3 MEDIUM |
| A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0. | |||||
| CVE-2026-78981 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-27 | N/A | 6.5 MEDIUM |
| Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local program. (Chromium security severity: Low) | |||||
| CVE-2026-43670 | 1 Apple | 4 Ipados, Iphone Os, Macos and 1 more | 2026-08-27 | N/A | 8.8 HIGH |
| A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy. | |||||
| CVE-2026-65367 | 1 Apple | 2 Ipados, Iphone Os | 2026-08-27 | N/A | 5.5 MEDIUM |
| A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination. | |||||
| CVE-2026-79207 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-27 | N/A | 6.5 MEDIUM |
| Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low) | |||||
| CVE-2026-79284 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 4.3 MEDIUM |
| UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79150 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-79140 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79128 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79091 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79069 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 8.8 HIGH |
| Memory corruption in Tint in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-79064 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) | |||||
| CVE-2026-79039 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-27 | N/A | 8.1 HIGH |
| Use after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | |||||
| CVE-2026-79012 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-78964 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-78935 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-79041 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-27 | N/A | 4.3 MEDIUM |
| Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low) | |||||
