Vulnerabilities (CVE)

Filtered by vendor Apple Subscribe
Filtered by product Macos
Total 6967 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-17752 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 8.8 HIGH
Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17695 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 9.6 CRITICAL
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-17709 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 9.6 CRITICAL
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-17710 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 9.6 CRITICAL
Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-17711 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 9.6 CRITICAL
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-17712 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 8.8 HIGH
Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-17865 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 9.6 CRITICAL
Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17864 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 7.8 HIGH
Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
CVE-2026-17893 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 5.8 MEDIUM
Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17975 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 6.5 MEDIUM
Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17973 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 5.5 MEDIUM
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17966 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 6.2 MEDIUM
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17996 2 Apple, Google 2 Macos, Chrome 2026-08-03 N/A 6.2 MEDIUM
Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
CVE-2026-17950 2 Apple, Google 2 Macos, Chrome 2026-07-31 N/A 8.8 HIGH
Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)
CVE-2026-43767 1 Apple 1 Macos 2026-07-30 N/A 5.0 MEDIUM
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
CVE-2026-43781 1 Apple 1 Macos 2026-07-30 N/A 4.7 MEDIUM
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
CVE-2026-43806 1 Apple 1 Macos 2026-07-30 N/A 5.5 MEDIUM
A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be able to cause a denial of service.
CVE-2026-64698 1 Apple 1 Macos 2026-07-30 N/A 9.8 CRITICAL
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or read kernel memory.
CVE-2026-64702 1 Apple 1 Macos 2026-07-30 N/A 9.8 CRITICAL
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.
CVE-2026-64713 1 Apple 7 Ipados, Iphone Os, Macos and 4 more 2026-07-30 N/A 8.1 HIGH
This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.