Vulnerabilities (CVE)

Filtered by vendor Apple Subscribe
Filtered by product Macos
Total 6967 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-10571 4 Apple, Ibm, Linux and 1 more 7 Macos, Aix, I and 4 more 2026-08-17 N/A 5.7 MEDIUM
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled.
CVE-2026-14525 4 Apple, Ibm, Linux and 1 more 7 Macos, Aix, I and 4 more 2026-08-17 N/A 9.4 CRITICAL
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
CVE-2026-19557 2 Apple, Google 2 Macos, Chrome 2026-08-17 N/A 8.3 HIGH
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-62899 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 5.9 MEDIUM
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62900 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 5.9 MEDIUM
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62901 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 7.5 HIGH
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62909 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 7.8 HIGH
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62871 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-13 N/A 7.8 HIGH
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-11980 4 Apple, Ibm, Linux and 1 more 4 Macos, Aspera, Linux Kernel and 1 more 2026-08-13 N/A 7.3 HIGH
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
CVE-2026-14973 4 Apple, Ibm, Linux and 1 more 4 Macos, Aspera, Linux Kernel and 1 more 2026-08-13 N/A 9.3 CRITICAL
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
CVE-2026-17716 2 Apple, Google 2 Macos, Chrome 2026-08-10 N/A 8.4 HIGH
Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via malicious network traffic. (Chromium security severity: High)
CVE-2026-17654 2 Apple, Google 2 Macos, Chrome 2026-08-06 N/A 7.8 HIGH
Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)
CVE-2026-39875 1 Apple 1 Macos 2026-08-05 N/A 7.8 HIGH
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
CVE-2026-18015 2 Apple, Google 2 Macos, Chrome 2026-08-04 N/A 9.6 CRITICAL
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17770 2 Apple, Google 2 Macos, Chrome 2026-08-04 N/A 5.8 MEDIUM
Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17784 2 Apple, Google 2 Macos, Chrome 2026-08-04 N/A 8.8 HIGH
Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2022-2294 6 Apple, Fedoraproject, Google and 3 more 12 Ipados, Iphone Os, Mac Os X and 9 more 2026-08-04 N/A 8.8 HIGH
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2026-17855 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 9.6 CRITICAL
Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17856 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 9.6 CRITICAL
Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17746 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 5.8 MEDIUM
Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)