apple / macos
1,342 known vulnerabilities in apple macos.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-10975 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10982 | Medium | 0.5% | 8.8 | Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-11003 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-64691 | Medium | 0.4% | 9.8 | A buffer overflow was addressed with improved size validation. This issue is fix… | |
| CVE-2026-17712 | Medium | 0.4% | 8.8 | Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote att… | |
| CVE-2026-43815 | Medium | 0.4% | 8.8 | A buffer overflow was addressed with improved bounds checking. This issue is fix… | |
| CVE-2026-28931 | Medium | 0.4% | 8.8 | A buffer overflow was addressed with improved bounds checking. This issue is fix… | |
| CVE-2026-65343 | Medium | 0.4% | 7.5 | A use after free issue was addressed with improved memory management. This issue… | |
| CVE-2026-84544 | Medium | 0.4% | 7.5 | An integer overflow was addressed with improved input validation. This issue is … | |
| CVE-2026-34711 | Medium | 0.4% | 7.5 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are af… | |
| CVE-2026-64783 | Medium | 0.4% | 8.8 | A use-after-free issue was addressed with improved memory management. This issue… | |
| CVE-2026-10910 | Medium | 0.4% | 8.8 | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote at… | |
| CVE-2026-7337 | Medium | 0.4% | 8.8 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote a… | |
| CVE-2026-87607 | Medium | 0.4% | 9.6 | Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allow… | |
| CVE-2026-7336 | Medium | 0.4% | 8.8 | Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remo… | |
| CVE-2026-10941 | Medium | 0.4% | 8.8 | Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-34622 | Medium | 0.4% | 8.6 | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are… | |
| CVE-2026-19297 | Medium | 0.4% | 9.1 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain una… | |
| CVE-2026-28911 | Medium | 0.4% | 9.8 | The issue was addressed with improved memory handling. This issue is fixed in ma… | |
| CVE-2026-84516 | Medium | 0.4% | 8.1 | An out-of-bounds read was addressed with improved bounds checking. This issue is… | |
| CVE-2026-34617 | Medium | 0.4% | 8.7 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Sc… | |
| CVE-2026-64719 | Medium | 0.4% | 8.1 | An out-of-bounds access issue was addressed with improved bounds checking. This … | |
| CVE-2026-9939 | Medium | 0.4% | 8.8 | Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allow… | |
| CVE-2026-10904 | Medium | 0.4% | 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allow… | |
| CVE-2026-10928 | Medium | 0.4% | 8.8 | Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-17752 | Medium | 0.4% | 8.8 | Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a… | |
| CVE-2026-17784 | Medium | 0.4% | 8.8 | Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a… | |
| CVE-2026-43805 | Medium | 0.4% | 9.8 | A race condition was addressed with improved state handling. This issue is fixed… | |
| CVE-2026-43731 | Medium | 0.4% | 8.8 | A use-after-free issue was addressed with improved memory management. This issue… | |
| CVE-2026-10887 | Medium | 0.4% | 8.1 | Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allo… | |
| CVE-2026-58641 | Medium | 0.4% | 7.8 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevat… | |
| CVE-2025-43264 | Medium | 0.4% | 8.8 | The issue was addressed with improved memory handling. This issue is fixed in ma… | |
| CVE-2026-19306 | Medium | 0.4% | 7.7 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read a… | |
| CVE-2026-15899 | Medium | 0.4% | 9.6 | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 … | |
| CVE-2026-62871 | Medium | 0.4% | 7.8 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code loca… | |
| CVE-2026-9118 | Medium | 0.4% | 8.8 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed… | |
| CVE-2026-9126 | Medium | 0.4% | 8.8 | Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remo… | |
| CVE-2026-87470 | Medium | 0.4% | 9.6 | Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8… | |
| CVE-2026-87558 | Medium | 0.4% | 9.6 | Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 all… | |
| CVE-2026-65390 | Medium | 0.4% | 8.8 | An integer overflow was addressed with improved input validation. This issue is … | |
| CVE-2026-65391 | Medium | 0.4% | 8.8 | An out-of-bounds write issue was addressed with improved bounds checking. This i… | |
| CVE-2026-10935 | Medium | 0.4% | 8.8 | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote at… | |
| CVE-2026-10936 | Medium | 0.4% | 8.8 | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote at… | |
| CVE-2026-10962 | Medium | 0.4% | 8.8 | Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-10881 | Medium | 0.4% | 9.6 | Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 al… | |
| CVE-2026-10883 | Medium | 0.4% | 8.8 | Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-10895 | Medium | 0.4% | 8.8 | Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-10902 | Medium | 0.4% | 8.8 | Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-10954 | Medium | 0.4% | 8.8 | Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-10956 | Medium | 0.4% | 8.8 | Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 allowe… |