LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Apple

187 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical58
High128
Medium1
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-65400exploited9.8criticalmacosAn authentication issue was addressed with improved state management.30d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-437489.8criticalmacosAn out-of-bounds write issue was addressed with improved bounds checking.40d ago
CVE-2026-437109.8criticalmacosThe issue was addressed with improved memory handling.40d ago
CVE-2026-436949.8criticalmacosThe issue was addressed with improved memory handling.40d ago
CVE-2026-647709.8criticalipadosAn out-of-bounds write issue was addressed with improved bounds checking.40d ago
CVE-2026-436829.8criticalmacosThe issue was addressed with improved memory handling.40d ago
CVE-2026-647699.8criticalipadosAn out-of-bounds write issue was addressed with improved bounds checking.40d ago
CVE-2026-398739.8criticalmacosThe issue was addressed with improved memory handling.40d ago
CVE-2026-289829.8criticalmacosA race condition was addressed with improved locking.40d ago
CVE-2026-289289.8criticalipadosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-437509.8criticalmacosA buffer overflow was addressed with improved bounds checking.40d ago
CVE-2026-437309.8criticalipadosA permissions issue was addressed with additional restrictions.40d ago
CVE-2026-289119.8criticalmacosThe issue was addressed with improved memory handling.40d ago
CVE-2026-647679.8criticalmacosA buffer overflow was addressed with improved bounds checking.40d ago
CVE-2026-647629.8criticalmacosAn out-of-bounds read was addressed with improved bounds checking.40d ago
CVE-2026-647519.8criticalipadosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-647469.8criticalipadosAn authorization issue was addressed with improved validation.40d ago
CVE-2026-647389.8criticalmacosA permissions issue was addressed with additional restrictions.40d ago
CVE-2026-647339.8criticalipadosThis issue was addressed with improved data protection.40d ago
CVE-2026-647319.8criticalmacosA path handling issue was addressed with improved validation.40d ago
CVE-2026-647299.8criticalipadosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-65400exploited9.8criticalmacosAn authentication issue was addressed with improved state management.30d ago
CVE-2026-647279.8criticalmacosA type confusion issue was addressed with improved memory handling.40d ago
CVE-2026-647269.8criticalipadosThe issue was addressed with improved memory handling.40d ago
CVE-2026-647209.8criticalipadosA race condition was addressed with improved state handling.40d ago
CVE-2026-647049.8criticalmacosA type confusion issue was addressed with improved memory handling.40d ago
CVE-2026-647039.8criticalmacosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-647759.8criticalipadosA memory initialization issue was addressed with improved memory handling.40d ago
CVE-2026-647029.8criticalmacosAn access issue was addressed with additional sandbox restrictions.40d ago
CVE-2026-647009.8criticalipadosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-646989.8criticalmacosThe issue was addressed with improved memory handling.40d ago
CVE-2026-647749.8criticalipadosAn integer overflow was addressed with improved input validation.40d ago
CVE-2026-646979.8criticalmacosThe issue was addressed with improved memory handling.40d ago
CVE-2026-646969.8criticalmacosThe issue was addressed with improved memory handling.40d ago
CVE-2026-646959.8criticalmacosThe issue was addressed with improved memory handling.40d ago
CVE-2026-646949.8criticalmacosAn integer overflow was addressed with improved input validation.40d ago
CVE-2026-437989.8criticalswiftnio sshA single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-co16d ago
CVE-2026-646919.8criticalmacosA buffer overflow was addressed with improved size validation.40d ago
CVE-2026-438229.8criticalipadosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-438149.8criticalipadosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-438129.8criticalipadosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-438109.8criticalipadosThe issue was addressed with improved memory handling.40d ago
CVE-2026-438099.8criticalmacosAn out-of-bounds read was addressed with improved bounds checking.40d ago
CVE-2026-438079.8criticalipadosA buffer overflow was addressed with improved bounds checking.40d ago
CVE-2026-647729.8criticalipadosAn out-of-bounds write issue was addressed with improved input validation.40d ago
CVE-2026-438059.8criticalipadosA race condition was addressed with improved state handling.40d ago
CVE-2026-438039.8criticalipadosAn out-of-bounds write issue was addressed with improved bounds checking.40d ago
CVE-2026-438029.8criticalmacosAn out-of-bounds write issue was addressed with improved bounds checking.40d ago
CVE-2026-437999.8criticalipadosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-437939.8criticalmacosAn issue existed in the handling of environment variables.40d ago
CVE-2026-647719.8criticalipadosA buffer overflow was addressed with improved bounds checking.40d ago
CVE-2026-437799.8criticalmacosA logic issue was addressed with improved restrictions.40d ago
CVE-2026-437789.8criticalipadosA use after free issue was addressed with improved memory management.40d ago
CVE-2026-437739.8criticalmacosAn out-of-bounds read was addressed with improved bounds checking.40d ago
CVE-2026-437699.8criticalipadosAn integer overflow was addressed with improved input validation.40d ago
CVE-2026-437649.8criticalmacosAn integer overflow was addressed with improved input validation.40d ago
CVE-2026-437579.8criticalmacosAn out-of-bounds read was addressed with improved bounds checking.40d ago
CVE-2026-647409.3criticalipadosA parsing issue in the handling of directory paths was addressed with improved path validation.40d ago
CVE-2026-398689.1criticalipadosThis issue was addressed with improved input validation.68d ago
CVE-2026-437158.8highsafariA use-after-free issue was addressed with improved memory management.68d ago
CVE-2023-430108.8highsafariThe issue was addressed with improved memory handling.178d ago
CVE-2026-288478.8highipadosThe issue was addressed with improved memory handling.117d ago
CVE-2026-289238.8highmacosA logging issue was addressed with improved data redaction.117d ago
CVE-2026-289408.8highipadosThe issue was addressed with improved memory handling.117d ago
CVE-2026-289478.8highipadosA use-after-free issue was addressed with improved memory management.117d ago
CVE-2026-289558.8highipadosThe issue was addressed with improved memory handling.117d ago
CVE-2026-289788.8highmacosA permissions issue was addressed with additional restrictions.117d ago
CVE-2026-289958.8highipadosA logic issue was addressed with improved restrictions.117d ago
CVE-2025-435248.8highmacosAn access issue was addressed with additional sandbox restrictions.116d ago
CVE-2025-242848.8highmacosThis issue was addressed with improved checks to prevent unauthorized actions.86d ago
CVE-2026-437058.8highsafariA type confusion issue was addressed with improved checks.68d ago
CVE-2026-437318.8highsafariA use-after-free issue was addressed with improved memory management.68d ago
CVE-2026-289318.8highipadosA buffer overflow was addressed with improved bounds checking.40d ago
CVE-2026-438188.8highipadosAn integer overflow was addressed with improved input validation.40d ago
CVE-2026-647398.8highipadosAn out-of-bounds write issue was addressed with improved bounds checking.40d ago
CVE-2026-647578.8highsafariA memory corruption issue was addressed with improved state management.40d ago
CVE-2026-647838.8highsafariA use-after-free issue was addressed with improved memory management.40d ago
CVE-2026-437948.8highsafariA memory corruption issue was addressed with improved memory handling.19d ago
CVE-2026-653468.8highipadosAn integer overflow was addressed with improved input validation.19d ago
CVE-2026-436708.8highsafariA Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts.11d ago
CVE-2026-437608.6highmacosAn access issue was addressed with improved access restrictions.40d ago
CVE-2026-289738.6highipadosAn integer overflow was addressed with improved input validation.40d ago
CVE-2026-437728.2highmacosA path traversal issue was addressed with improved input validation.40d ago
CVE-2026-647378.2highmacosAn authorization issue was addressed with improved state management.40d ago
CVE-2026-647688.1highipadosAn out-of-bounds read issue was addressed with improved input validation.40d ago
CVE-2026-437358.1highsafariThe issue was addressed with improved checks.68d ago
CVE-2026-289078.1highipadosThe issue was addressed with improved input validation.117d ago
CVE-2026-647198.1highsafariAn out-of-bounds access issue was addressed with improved bounds checking.40d ago
CVE-2026-647138.1highsafariThis issue was addressed with improved checks.40d ago
CVE-2025-312727.8highmacosThe issue was addressed with improved checks.86d ago
CVE-2026-647637.8highipadosAn out-of-bounds write issue was addressed by removing the vulnerable code.40d ago
CVE-2026-437337.8highipadosThe issue was addressed with improved memory handling.40d ago
CVE-2026-647587.8highipadosThe issue was addressed with improved bounds checks.40d ago
CVE-2025-433067.8highmacosA logic issue was addressed with improved checks.102d ago
CVE-2026-398747.8highmacosA permissions issue was addressed with additional restrictions.40d ago
CVE-2026-647497.8highipadosThe issue was addressed with improved memory handling.40d ago
CVE-2026-437497.8highmacosA parsing issue in the handling of directory paths was addressed with improved path validation.40d ago
CVE-2026-398757.8highmacosA permissions issue was addressed with additional restrictions.40d ago
CVE-2026-647667.8highipadosAn integer overflow was addressed with improved input validation.40d ago
CVE-2026-647477.8highipadosA buffer overflow was addressed with improved size validation.40d ago
CVE-2026-647657.8highipadosAn integer overflow was addressed with improved input validation.40d ago

Filter the full tracker by Apple

Our coverage of Apple

security

Researcher tricks Apple’s Find My into sharing location data with Linux

Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget

vulnerability

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek.

CVE-2026-33824

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchan

patch

Apple plugs image-processing hole ripe for spyware abuse

Patch batch spans current kit, older iGadgets, Macs, and Vision Pro

vulnerability

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.

nation-state

Apple Screen Sharing Security, (Mon, Aug 17th)

About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used a simple global password for authentication. Apple adapted the protocol for its own use, but overall, left the VNC prot

spywarehigh

Apple Warns Hundreds of Targeted Mercenary Spyware Attacks

Apple has issued new threat notifications to hundreds of users across 110 countries, warning them of credible, targeted mercenary spyware attacks. These sophisticated attacks, which are distinct from regular cybercriminal activity, are likely aimed at individuals due to their identity or profession, such as journalists, activists, and politicians. The company is urging affected users to verify their security, implement stronger protections, and seek expert assistance.

security

Apple now uses iPhone alerts for targets of mercenary spyware

Apple explains how Threat Notifications help protect iPhone users targeted by mercenary spyware.

security

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]

data center technology

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

Several cybersecurity incidents are highlighted, including a ban on Chinese data center technology, a supply chain attack on QuickFox VPN, and a phishing breach at IEH Corporation. Additionally, AI-generated content may be impacting Apple's bug bounty program, and a North Carolina port experienced an attack, alongside broader targeting of Wall Street.

vulnerabilitycritical

Microsoft, Apple Release Fresh Security Updates

Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek.

vulnerability

Apple WebKit vulnerabilities reveal your IP address, despite Private Relay

Researchers have found three methods to bypass Apple's Private Relay which is supposed to shield users' IP addresses and location.