By vendor
Apple vulnerabilities
Known CVEs affecting Apple products, prioritized by severity, with SEC.co remediation and detection guidance.
712 published vulnerabilities · page 3 of 8
- CVE-2026-11642HIGH 8.3
Google Chrome prior to version 149.0.7827.103 contains a use-after-free vulnerability in its web application handling that could allow a remote attacker to escape the browser's sandbox. The attack requires the attacker to first compromise the renderer process—a separate security boundary within Chrome—and then trick a user into visiting a malicious website. If successful, the attacker could potentially gain system-level access, though the vulnerability itself is triggered through browser interaction rather than automatic exploitation.
- CVE-2026-11652HIGH 8.3
Google Chrome versions before 149.0.7827.103 contain a use-after-free vulnerability in its extension handling code that could allow an attacker to escape the browser sandbox. An attacker who has already compromised the Chrome renderer process—the isolated process that runs website code—could exploit this flaw by crafting a malicious HTML page to gain code execution outside the sandbox, potentially compromising the entire system. The vulnerability requires user interaction (such as visiting a malicious site) and a prior renderer compromise, making it a secondary exploitation vector rather than a direct entry point.
- CVE-2026-11655HIGH 8.3
A mathematical error in how Google Chrome handles media files on macOS allows an attacker to escape the browser's sandbox if they've already compromised Chrome's rendering engine. The vulnerability exists in versions before 149.0.7827.103 and requires a specially crafted webpage to trigger. Once exploited, an attacker could move from the restricted sandbox environment to full system access.
- CVE-2026-11656HIGH 8.3
A use-after-free vulnerability exists in Google Chrome's ServiceWorker component that could allow attackers to escape the browser sandbox if they can trick a user into installing a malicious Chrome extension. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction to install the extension, but successful exploitation would grant an attacker access to the underlying system beyond Chrome's normal security boundaries.
- CVE-2026-11660HIGH 8.3
A vulnerability in Google Chrome's New Tab Page feature allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox using a specially crafted HTML page. This is a critical privilege escalation risk because sandbox escapes can lead to full system compromise. The vulnerability affects Chrome versions before 149.0.7827.103 across Windows, macOS, and Linux.
- CVE-2026-11663HIGH 8.3
A use-after-free memory flaw exists in Google Chrome's Skia rendering engine. If an attacker first compromises Chrome's renderer process—the sandboxed component responsible for drawing web content—they can craft a malicious HTML page to trigger the vulnerability and break out of the sandbox, gaining full system access. This is a post-compromise attack chain: the renderer must already be compromised, but once it is, the attacker bypasses Chrome's key security boundary.
- CVE-2026-11677HIGH 8.3
A race condition vulnerability in Google Chrome's network process on macOS allows an attacker who has already compromised the browser's network process to escape the sandbox and potentially gain system-level access. The vulnerability requires the attacker to craft a malicious HTML page and trick a user into viewing it, but the underlying network process compromise is the critical prerequisite. This is a privilege escalation vector rather than a primary infection method.
- CVE-2026-11692HIGH 8.3
A use-after-free vulnerability in Chrome's Read Anything feature allows an attacker who has already compromised the browser's renderer process to escape the sandbox and gain elevated system privileges. The attacker needs a user to open a malicious HTML page, but once triggered, the flaw breaks Chrome's security isolation and can lead to full system compromise. Google Chrome versions prior to 149.0.7827.103 are affected across Windows, macOS, and Linux.
- CVE-2026-11700HIGH 8.3
A use-after-free flaw in Chrome's tracing component allows an attacker who has already compromised the renderer process to escape the browser sandbox through a specially crafted HTML page. While the attack requires the renderer to be compromised first, successful exploitation could give an attacker full system access beyond the browser's security boundaries.
- CVE-2026-12008HIGH 8.3
A use-after-free vulnerability in Google Chrome's DigitalCredentials component allows attackers who have already compromised a browser's renderer process to potentially break out of Chrome's sandbox and gain system-level access. The flaw affects Chrome versions before 149.0.7827.115 and requires an attacker to serve a specially crafted webpage to trigger it. While the initial compromise of the renderer is a necessary prerequisite, successfully exploiting this vulnerability could give an attacker the ability to execute arbitrary code outside the browser's security boundaries.
- CVE-2026-12009HIGH 8.3
Google Chrome on macOS contains a vulnerability in its Accessibility feature that could allow an attacker to escape the browser's sandbox—a critical security boundary—if they first compromised Chrome's rendering engine. The flaw stems from insufficient validation of untrusted input. An attacker would need to trick a user into visiting a specially crafted webpage while having already compromised the renderer process, making this a two-stage attack. Versions prior to 149.0.7827.115 are affected.
- CVE-2026-12014HIGH 8.3
Google Chrome versions prior to 149.0.7827.115 contain a use-after-free memory vulnerability in the Cast feature that allows an attacker with access to the local network to escape the browser sandbox. The vulnerability requires specific conditions to trigger but, if successfully exploited, could grant an attacker code execution outside the browser's security boundaries. This is a local network attack vector, not a remote internet-wide threat, but poses significant risk in environments where untrusted devices share the same network segment.
- CVE-2026-12016HIGH 8.3
Google Chrome versions before 149.0.7827.115 contain a vulnerability in the DevTools component that allows an attacker to escape the browser's sandbox. The attack requires two preconditions: the attacker must first compromise Chrome's renderer process (the component that executes web content), and the victim must interact with a specially crafted HTML page. Successfully exploiting this flaw could give an attacker full system access, bypassing Chrome's security isolation layer.
- CVE-2026-12022HIGH 8.3
A race condition in Google Chrome's Safe Browsing feature on macOS allows an attacker who has already compromised the browser's renderer process to escape the sandbox using a specially crafted file. This means an attacker would need to first gain code execution within Chrome itself, then exploit this timing vulnerability to break out of Chrome's security boundary and gain full system access. The vulnerability affects Chrome versions prior to 149.0.7827.115 on Mac.
- CVE-2026-12023HIGH 8.3
A use-after-free memory flaw exists in the GPU processing component of Google Chrome on macOS. An attacker who has already compromised Chrome's renderer process could exploit this defect via a specially crafted HTML page to escape the browser's security sandbox and execute arbitrary code with elevated privileges. This is a post-compromise attack path—it requires the renderer to be under attacker control first, but the sandbox escape amplifies the damage significantly.
- CVE-2026-12451HIGH 8.3
Google Chrome versions before 149.0.7827.155 contain a use-after-free vulnerability in the DigitalCredentials component that can allow attackers who have already compromised the renderer process to break out of Chrome's sandbox and potentially execute arbitrary code on the host system. The vulnerability requires both renderer compromise and user interaction, making it a multi-stage attack chain. An attacker would first need to trick a user into visiting a malicious webpage, then leverage this flaw to escape Chrome's security boundaries.
- CVE-2026-12454HIGH 8.3
CVE-2026-12454 is a race condition flaw in Google Chrome's Safe Browsing feature on macOS that allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox and gain access to the underlying system. The vulnerability requires a specially crafted HTML page and user interaction, but once triggered, it can lead to complete system compromise. This is a high-severity issue because successful exploitation means an attacker can move from browser isolation into full OS-level execution.
- CVE-2026-12464HIGH 8.3
A use-after-free memory vulnerability in Google Chrome's browser engine allows an attacker who has already compromised the renderer process to break out of the browser's sandbox and potentially execute arbitrary code with full system privileges. The vulnerability requires an attacker to first gain control of Chrome's renderer (the process that interprets web pages), then serve a specially crafted HTML page to trigger the memory corruption. This is a high-severity issue because sandbox escapes eliminate one of Chrome's primary security boundaries.
- CVE-2026-12465HIGH 8.3
CVE-2026-12465 is a sandbox escape vulnerability in Google Chrome that stems from improper handling of object lifecycles in the Metrics component. An attacker who has already compromised Chrome's renderer process can exploit a crafted HTML page to break out of the browser sandbox and gain access to the underlying system. This is a post-compromise escalation path that requires the renderer to be compromised first, but once achieved, allows full system access.
- CVE-2026-12467HIGH 8.3
Google Chrome versions before 149.0.7827.155 contain a use-after-free memory safety vulnerability in the Extensions system. An attacker who has already compromised a Chrome renderer process could exploit this flaw via a malicious HTML page to break out of Chrome's sandbox and gain full system access. The vulnerability requires user interaction (opening a crafted page) and successful renderer compromise, but once those conditions are met, the sandbox escape could be severe.
- CVE-2026-12468HIGH 8.3
A race condition in Chrome's auto-update mechanism on macOS allows an attacker who has already compromised the browser's rendering engine to escape the sandbox and gain full system privileges. The vulnerability requires the attacker to first breach the renderer process (a less privileged part of Chrome) through a malicious web page, then exploit a timing flaw in the updater to break out of Chrome's security isolation. This is a chained attack: the initial compromise is necessary, but once achieved, the sandbox escape becomes a critical escalation path. Chrome versions before 149.0.7827.155 on macOS are affected.
- CVE-2026-13025HIGH 8.3
A race condition in Google Chrome's Developer Tools allows attackers who have already compromised Chrome's renderer process to break out of Chrome's security sandbox and gain access to the underlying operating system. The vulnerability requires the attacker to deliver a specially crafted webpage, but can lead to complete system compromise. This affects Chrome versions before 149.0.7827.197.
- CVE-2026-13281HIGH 8.3
CVE-2026-13281 is a high-severity integer overflow vulnerability in the Mojo component of Google Chrome that could allow an attacker to escape the browser's sandbox if they first compromise the renderer process. An attacker would need to trick a user into opening a malicious file while controlling the renderer, creating a two-stage attack pathway. Successful exploitation could grant an attacker full system-level access beyond Chrome's security boundaries.
- CVE-2026-13801HIGH 8.3
Google Chrome contains an integer overflow vulnerability in its Chromecast implementation that could allow an attacker to escape the browser's security sandbox. The flaw requires the attacker to first compromise the renderer process—the part of Chrome that executes web content—and then trick a user into visiting a specially crafted webpage. If successful, an attacker could break out of Chrome's sandbox isolation and gain access to the underlying operating system. This vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux.
- CVE-2026-13813HIGH 8.3
A security flaw in Google Chrome for iOS allows attackers who have already compromised Chrome's rendering engine to break out of the browser's sandbox—a protective boundary designed to limit damage if a web page is malicious. The attacker would need to craft a specially designed webpage to trigger the escape. This vulnerability affects Chrome versions before 150.0.7871.47 on iOS devices.
- CVE-2026-9877HIGH 8.3
A use-after-free memory vulnerability in the ANGLE graphics library affects Google Chrome versions before 148.0.7778.216. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox and gain unauthorized system access. While the attack requires an existing foothold in the renderer, the critical severity designation reflects the severe consequences of a successful sandbox escape.
- CVE-2026-9880HIGH 8.3
Google Chrome versions before 148.0.7778.216 contain a flaw in WebGL input validation that allows an attacker who has already compromised the browser's renderer process to escape the browser sandbox and gain full system access. The vulnerability requires user interaction (clicking or otherwise engaging with a malicious page) but poses a critical risk once that initial renderer compromise occurs.
- CVE-2026-9885HIGH 8.3
A flaw in how Google Chrome validates user interface input on macOS versions prior to 148.0.7778.216 could allow an attacker who has already compromised the browser's rendering engine to break out of Chrome's sandbox. The attacker would need to trick a user into visiting a specially crafted webpage, but once the renderer is compromised, this vulnerability provides a pathway to execute code outside the sandbox with full system privileges.
- CVE-2026-9925HIGH 8.3
A use-after-free flaw in ANGLE (the graphics abstraction layer used by Google Chrome) can allow an attacker to escape the browser sandbox if they first compromise the renderer process. The attacker would craft a malicious HTML page to trigger memory corruption that leads to code execution outside the sandbox boundary. This requires two conditions: initial renderer compromise and user interaction with the hostile page.
- CVE-2026-9926HIGH 8.3
A memory error in Chrome's graphics processing component (ANGLE) could allow an attacker who has already compromised the renderer process to break out of the sandbox and access the wider system. The vulnerability requires the attacker to deliver a specially crafted webpage and the user to interact with it, but once triggered, it could lead to full system compromise. The issue affects Chrome versions prior to 148.0.7778.216.
- CVE-2026-9931HIGH 8.3
A use-after-free memory flaw in Chrome's GPU component allows an attacker who has already compromised the browser's renderer process to break out of Chrome's sandbox and gain system-level access. The attacker would need to trick a user into visiting a malicious webpage while the renderer is already under attack. This is a post-compromise privilege escalation path rather than a direct remote attack vector.
- CVE-2026-9936HIGH 8.3
A use-after-free vulnerability in Google Chrome's graphics rendering engine (GFX) affects Mac systems running versions prior to 148.0.7778.216. The flaw allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox through a malicious HTML page, potentially gaining access to the underlying operating system. This is a post-compromise attack requiring the renderer to already be under attacker control.
- CVE-2026-9946HIGH 8.3
A use-after-free vulnerability in Google Chrome's ANGLE graphics library could allow an attacker who has already compromised the browser's renderer process to break out of Chrome's security sandbox and execute code with system-level privileges. The flaw affects Chrome versions before 148.0.7778.216 and requires user interaction—typically visiting a malicious website—to trigger the vulnerability chain.
- CVE-2026-9948HIGH 8.3
Google Chrome on macOS contains a use-after-free vulnerability in its Views component that could allow an attacker to escape the browser's sandbox. The attack requires two conditions: the attacker must first compromise Chrome's renderer process (the sandboxed component that executes web content), and the victim must interact with a specially crafted webpage. If successful, the attacker gains access beyond the sandbox, potentially compromising the entire system. This vulnerability affects Chrome versions prior to 148.0.7778.216 on macOS.
- CVE-2026-9951HIGH 8.3
Google Chrome before version 148.0.7778.216 contains a use-after-free vulnerability in its user interface rendering engine. This flaw allows an attacker to craft a malicious HTML page that, when visited by a user, can trigger memory corruption. The vulnerability is particularly dangerous because it may enable attackers to break out of Chrome's sandbox—the security boundary that isolates the browser from the underlying operating system—potentially gaining direct access to system resources and user data. Exploitation requires user interaction (clicking or visiting a malicious site) and involves complex attack conditions, but the potential for sandbox escape elevates the risk significantly.
- CVE-2026-9970HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's WebGL component that could allow an attacker to escape the browser sandbox. An attacker would first need to compromise Chrome's renderer process—typically through a separate exploit or social engineering—and then could use a specially crafted HTML page to gain unauthorized access outside the browser's security boundaries. This vulnerability affects Chrome versions before 148.0.7778.216 on Windows, macOS, and Linux systems.
- CVE-2026-9972HIGH 8.3
A vulnerability in Google Chrome on macOS could allow an attacker to escape the browser's security sandbox if the attacker has already compromised Chrome's renderer process. The flaw stems from uninitialized memory in the gamepad handling code. An attacker would need to trick a user into visiting a malicious website while Chrome is running, and would require a prior compromise of the renderer—a critical prerequisite that significantly limits real-world exploitation scenarios. Once exploited, the attacker could potentially gain full system access beyond Chrome's normal restrictions.
- CVE-2026-9974HIGH 8.3
CVE-2026-9974 is a memory safety bug in Google Chrome's GPU rendering component that can allow an attacker to escape the browser's sandbox if they first compromise the renderer process. The vulnerability stems from an out-of-bounds write operation, meaning the code writes data outside its intended memory boundaries. An attacker would need to trick a user into visiting a malicious webpage while already having control of Chrome's renderer, making this a secondary exploit that amplifies damage from other browser compromises.
- CVE-2026-9975HIGH 8.3
A memory safety vulnerability in Google Chrome's ANGLE graphics library allows an attacker who has already compromised the browser's renderer process to break out of Chrome's sandbox and gain full system access. The flaw involves reading and writing memory beyond intended boundaries, creating a bridge from the restricted renderer environment to the host operating system. This requires the attacker to first successfully compromise the renderer (through a separate browser exploit or vulnerability) and then craft a malicious HTML page to trigger the escape.
- CVE-2026-9982HIGH 8.3
CVE-2026-9982 is a sandbox escape vulnerability in Google Chrome's ANGLE graphics library. An attacker who has already compromised the browser's renderer process can exploit insufficient input validation to break out of the sandbox and gain system-level access. This requires an attacker to first deliver a malicious webpage that triggers the rendering flaw, making it a chained attack scenario rather than a one-step exploitation path.
- CVE-2026-9993HIGH 8.3
A use-after-free memory vulnerability exists in Google Chrome's rendering engine that allows an attacker to escape the browser's sandbox if they have already compromised the renderer process. The vulnerability is triggered when a user opens a malicious PDF file. This is a critical threat because it could allow an attacker who has gained code execution within the browser to break out of Chrome's security boundaries and gain access to the underlying operating system.
- CVE-2026-9997HIGH 8.3
Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in the Input component that could allow an attacker to escape the browser's sandbox. The attack requires the attacker to have already compromised Chrome's renderer process and trick a user into visiting a malicious HTML page. If successful, the attacker could break out of the sandbox and gain access to the underlying operating system.
- CVE-2026-9998HIGH 8.3
CVE-2026-9998 is a high-severity integer overflow vulnerability in Google Chrome's Skia graphics library that could allow an attacker to escape the browser's sandbox—a critical security boundary—if they first compromise Chrome's renderer process. The vulnerability requires a specially crafted HTML page and user interaction, making it a significant but not trivial threat. The issue affects Chrome versions before 148.0.7778.216.
- CVE-2026-10887HIGH 8.1
A use-after-free flaw in Chrome's Chromoting remote desktop feature on macOS allows attackers to execute arbitrary code by sending specially crafted network traffic. The vulnerability exists in versions prior to 149.0.7827.53 and requires no user interaction—an attacker on the network can trigger the bug remotely, making this a critical threat to any Mac user running an affected Chrome version.
- CVE-2026-10930HIGH 8.1
An out-of-bounds read vulnerability in ANGLE (the graphics translation layer used by Chrome on macOS) allows attackers to read sensitive memory from your system by tricking you into visiting a malicious website. The flaw affects Chrome versions before 149.0.7827.53 on Apple macOS. While the attacker cannot directly modify data or take control of your system through this specific vulnerability, they can extract confidential information—including passwords, encryption keys, or other sensitive data stored in memory—and cause Chrome to crash.
- CVE-2026-11011HIGH 8.1
A flaw in Google Chrome's Password Manager allows an attacker who has already compromised the browser's renderer process to sidestep site isolation—a critical security boundary that prevents one website from accessing data belonging to another. By crafting a malicious HTML page, the attacker could potentially access sensitive information across different sites. This vulnerability affects Chrome versions before 149.0.7827.53 and requires the attacker to first gain control of the renderer process, which typically happens through a separate exploit or malicious website.
- CVE-2026-11015HIGH 8.1
A memory reading flaw in Google Chrome's WebGPU component allows attackers to read data outside the intended memory boundaries when a user visits a specially crafted website. The vulnerability requires user interaction (visiting a malicious page) but does not require special privileges, and while the attacker cannot modify data or directly crash the browser, they can extract sensitive information from the process's memory—such as passwords, keys, or other confidential data stored there.
- CVE-2026-11111HIGH 8.1
A memory reading vulnerability exists in Chrome's graphics engine (ANGLE) that allows attackers to access out-of-bounds data on a victim's system. An attacker could craft a malicious webpage that, when visited, leaks sensitive information from the browser's memory without modifying or corrupting system data. This affects Chrome versions prior to 149.0.7827.53. The vulnerability requires user interaction—a person must visit the malicious page—but once there, the attacker gains read access to protected memory regions.
- CVE-2026-11169HIGH 8.1
Google Chrome versions before 149.0.7827.53 contain a flaw in how they process XML files that allows attackers to inject malicious scripts or HTML content into a webpage, even when normal security protections should prevent it. An attacker would need to trick a user into opening a specially crafted XML file, but once successful, the injected code can execute with the same privileges as the user, potentially stealing data or taking other harmful actions. The vulnerability affects Chrome on Windows, macOS, and Linux systems.
- CVE-2026-11185HIGH 8.1
A use-after-free flaw in the V8 JavaScript engine affects Google Chrome versions before 149.0.7827.53. The vulnerability requires an attacker to trick a user into installing a malicious Chrome extension, which can then execute arbitrary code within the browser's sandbox. While the Chromium project rated this as Medium severity, the CVSS score of 8.1 reflects the high potential impact on confidentiality and integrity. This is a memory safety issue that leverages social engineering to gain code execution capabilities.
- CVE-2026-11231HIGH 8.1
Google Chrome on macOS contains a flaw in its Safe Browsing feature that could allow an attacker to run malicious code on a user's computer. The vulnerability requires user interaction—specifically, the user must open or interact with a malicious file. While Chromium's security team classified the underlying issue as low severity, the CVSS score of 8.1 reflects the real-world impact: an attacker gaining code execution on the system. This affects Chrome versions prior to 149.0.7827.53 on macOS.
- CVE-2026-11643HIGH 8.1
A use-after-free vulnerability exists in Google Chrome's Proxy component that could allow attackers to execute arbitrary code on victim machines through specially crafted network traffic. The flaw affects Chrome versions prior to 149.0.7827.103 and has been rated as Critical by the Chromium security team. While no active exploitation has been confirmed in the wild, the vulnerability's remote nature and code execution potential make it a significant threat requiring prompt patching.
- CVE-2026-11689HIGH 8.1
A vulnerability in Google Chrome versions before 149.0.7827.103 allows an attacker who has already compromised Chrome's renderer process to break through site isolation—Chrome's security boundary that keeps websites from accessing each other's data. An attacker would need to trick a user into visiting a malicious webpage after the renderer is already compromised, but if successful, they could read or modify sensitive information across different websites.
- CVE-2026-11693HIGH 8.1
Google Chrome versions before 149.0.7827.103 contain a flaw in how plugins are handled that allows a remote attacker to break through Chrome's site isolation security boundary. Site isolation is Chrome's defense mechanism that keeps different websites in separate processes to prevent one compromised site from accessing data from another. An attacker who has already compromised the renderer process—the part of Chrome that executes web pages—can craft a malicious HTML page to bypass this isolation, potentially gaining unauthorized access to sensitive data from other open websites or sessions.
- CVE-2026-12012HIGH 8.1
Google Chrome contains a use-after-free flaw in its network handling code that could allow attackers on a privileged network position to corrupt Chrome's memory and potentially execute code. The vulnerability affects Chrome versions before 149.0.7827.115 and is rated High severity. An attacker would need both network access and the ability to intercept or manipulate traffic, but would not need user interaction to trigger the flaw.
- CVE-2026-13774HIGH 8.1
A use-after-free memory vulnerability exists in Google Chrome's extension handling mechanism. An attacker can exploit this by tricking a user into installing a malicious Chrome extension, which could then execute arbitrary code with the privileges of the Chrome browser. The vulnerability affects Chrome versions before 150.0.7871.47 and is rated as high-severity by CVSS standards, though Google classifies the underlying issue as critical from a Chromium perspective.
- CVE-2026-13791HIGH 8.1
CVE-2026-13791 is a code execution vulnerability in Google Chrome's download handling system that affects versions prior to 150.0.7871.47. The flaw stems from insufficient validation of user-supplied input when processing malicious Chrome extensions. An attacker must first convince a user to install a specially crafted extension, but once installed, the extension can execute arbitrary code with the privileges of the Chrome process. This represents a post-installation code execution risk rather than a browser compromise via web browsing alone.
- CVE-2026-13799HIGH 8.1
A use-after-free defect in Google Chrome's QUIC protocol implementation allows attackers to trigger memory corruption by sending specially crafted network packets. An attacker can exploit this remotely without user interaction or special privileges. While the vulnerability requires specific network conditions to trigger (reflected in the CVSS complexity score), successful exploitation could enable arbitrary code execution on affected systems.
- CVE-2026-13819HIGH 8.1
A memory-reading vulnerability exists in the ANGLE graphics library within Google Chrome on macOS versions prior to 150.0.7871.47. An attacker who has already compromised Chrome's renderer process can craft a malicious web page to read data from outside the intended memory boundaries, potentially exposing sensitive information. The vulnerability requires the attacker to have already gained control of the renderer process, which typically happens after successful exploitation of another Chrome vulnerability.
- CVE-2026-13974HIGH 8.1
Google Chrome on macOS contains an integer overflow flaw in its Safe Browsing feature that allows an attacker to bypass navigation restrictions through a malicious file. The vulnerability requires user interaction—specifically, the user must open or download a malicious file—but once triggered, it can lead to integrity compromise and availability impact. This affects Chrome versions prior to 150.0.7871.47 on macOS systems.
- CVE-2026-14032HIGH 8.1
A use-after-free memory vulnerability exists in the Bluetooth implementation of Google Chrome on macOS. An attacker could exploit this by convincing a user to install a malicious Chrome extension, which could then execute arbitrary code with the privileges of the browser. While the Chromium project classified this as low severity internally, the CVSS score reflects the potential for complete system compromise once code execution is achieved.
- CVE-2026-14111HIGH 8.1
A use-after-free vulnerability exists in Google Chrome's WebProtect component that could allow an attacker to run malicious code on a user's system. The vulnerability requires social engineering—specifically convincing a user to install a malicious browser extension—but once that hurdle is cleared, an attacker can execute arbitrary code with the privileges of the Chrome process. This affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-43735HIGH 8.1
A vulnerability in Apple's Safari browser and related operating systems allows attackers to steal sensitive data from users by tricking them into visiting a malicious website. The flaw bypasses security boundaries that normally prevent websites from accessing data belonging to other websites, creating a cross-origin data leakage risk. Users must visit the malicious site for the attack to work, but no other user interaction beyond clicking a link is required.
- CVE-2026-9964HIGH 8.1
CVE-2026-9964 is a memory safety vulnerability in Chrome's Bluetooth implementation on macOS that can allow attackers to run malicious code on a victim's computer. The attack requires two user actions: the victim must first install a malicious Chrome extension, and then interact with Bluetooth functionality in a way that triggers the underlying flaw. Once those conditions are met, the attacker can execute arbitrary code with the same privileges as the Chrome process.
- CVE-2026-11241HIGH 8.0
A vulnerability in Google Chrome's Cast feature allows an attacker on your local network to escalate their privileges on an affected machine by tricking a user into visiting a specially crafted web page. The attack requires the attacker to already be on your network segment and the user to interact with the malicious page, but once triggered, it grants elevated system access. Google rates this as a low-severity issue in Chromium, yet the CVSS 3.1 score reflects broader impact potential including confidentiality, integrity, and availability compromise.
- CVE-2026-34693HIGH 8.0
Adobe Experience Manager Forms JEE is vulnerable to a reflected cross-site scripting (XSS) flaw that allows attackers to inject malicious code into web pages. When a victim visits a specially crafted URL or interacts with a compromised page, the attacker can potentially hijack the user's session, escalate privileges, or take over their account. The vulnerability affects LTS SP1 and version 6.5.24.0 and earlier. Successful exploitation requires social engineering—tricking a user into clicking a malicious link or visiting a compromised site—but does not require the attacker to have direct system access.
- CVE-2020-9695HIGH 7.8
Adobe Acrobat Reader contains a memory corruption flaw that allows attackers to execute arbitrary code on a user's system when a victim opens a specially crafted PDF file. The vulnerability affects multiple versions across Windows and macOS platforms. While the flaw is serious, it requires an attacker to socially engineer a user into opening a malicious document, making it a targeted rather than worm-like threat.
- CVE-2025-31272HIGH 7.8
A vulnerability in macOS allows locally authenticated applications to circumvent built-in launch constraint protections—security mechanisms designed to prevent unauthorized code execution. An attacker with local access could potentially run malicious code with elevated system privileges by exploiting a weakness in how these protections are enforced. Apple has patched this issue in macOS Sequoia 15.4 with stricter validation checks.
- CVE-2026-13778HIGH 7.8
A use-after-free vulnerability exists in Google Chrome's WebUSB implementation on macOS. When a user connects a malicious USB peripheral while Chrome is running, an attacker can trigger memory corruption that leads to arbitrary code execution with the privileges of the logged-in user. The flaw affects Chrome versions prior to 150.0.7871.47 on Mac systems and requires the user to interact with the malicious device; it cannot be exploited remotely.
- CVE-2026-13827HIGH 7.8
A use-after-free flaw in Chrome's Updater component on macOS allows a local attacker with standard user permissions to escalate privileges by tricking a user into opening a malicious file. The vulnerability exists in Chrome versions prior to 150.0.7871.47. While exploitation requires local access and user interaction, successful exploitation grants full system-level capabilities on the affected machine.
- CVE-2026-34695HIGH 7.8
Adobe InDesign versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a victim's computer. An attacker would need to trick a user into opening a malicious file—there is no remote exploitation vector. The vulnerability affects InDesign on both Windows and macOS systems.
- CVE-2026-34696HIGH 7.8
Adobe InDesign versions 21.3, 20.5.3 and earlier contain a Use After Free memory vulnerability that allows attackers to execute arbitrary code on a user's computer. The flaw requires a user to open a specially crafted malicious file—there is no remote attack vector. Once triggered, an attacker gains full control of the application and can read, modify, or delete user data, install malware, or pivot to other systems with the privileges of the logged-in user.
- CVE-2026-34697HIGH 7.8
Adobe InDesign Desktop has a stack-based buffer overflow flaw that allows attackers to run arbitrary code on your computer if you open a malicious file. The vulnerability affects InDesign version 21.3, 20.5.3, and earlier on both Windows and macOS. It requires user interaction—the attacker must trick you into opening a crafted document—but once triggered, the code runs with your user privileges. This is a serious issue because InDesign documents are commonly shared and trusted, making social engineering attacks plausible.
- CVE-2026-34698HIGH 7.8
Adobe InDesign Desktop contains a memory handling flaw that allows attackers to execute arbitrary code on a user's computer if the user opens a specially crafted file. The vulnerability affects InDesign versions 21.3, 20.5.3 and earlier on both Windows and macOS systems. While the flaw is serious, exploiting it requires social engineering or file delivery—an attacker cannot trigger it remotely over the network.
- CVE-2026-34699HIGH 7.8
Adobe InDesign Desktop contains a heap memory vulnerability that could allow an attacker to execute arbitrary code on a victim's computer. The flaw exists in versions 21.3, 20.5.3, and earlier on both Windows and macOS. An attacker would need to trick a user into opening a specially crafted file—such as an InDesign document—to trigger the vulnerability. If successful, the attacker gains the same permissions as the logged-in user, potentially enabling data theft, malware installation, or lateral movement within a network.
- CVE-2026-34700HIGH 7.8
Adobe InDesign versions 21.3, 20.5.3 and earlier contain a memory vulnerability that allows an attacker to execute arbitrary code on a victim's computer. The attack requires social engineering—a user must be tricked into opening a malicious file. Once opened, the flaw allows the attacker to run code with the same privileges as the InDesign user, potentially compromising the entire system. This is a serious but not trivial threat: it requires user interaction and affects only specific InDesign versions, but the payoff for an attacker is significant.
- CVE-2026-34701HIGH 7.8
Adobe InDesign Desktop has a memory safety flaw that allows attackers to execute arbitrary code on a victim's machine by crafting a malicious document. When an unsuspecting user opens the file in InDesign 21.3, 20.5.3, or earlier versions, the vulnerability is triggered, giving the attacker the same privileges as the user running InDesign. This is a serious risk for design teams and publishers who regularly work with untrusted or externally-sourced documents.
- CVE-2026-34702HIGH 7.8
Adobe InDesign versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow flaw that allows attackers to execute arbitrary code with the privileges of the user running InDesign. The vulnerability requires social engineering—an attacker must trick a user into opening a specially crafted file. Once opened, the malicious file triggers the overflow and grants the attacker code execution on the victim's machine. This affects both Windows and macOS deployments of InDesign.
- CVE-2026-34706HIGH 7.8
Adobe InCopy, a professional editorial software tool, contains a vulnerability that allows attackers to execute malicious code on a user's system when the user opens a specially crafted file. The flaw stems from improper memory handling (out-of-bounds write) that can be exploited to gain full control of the affected system under the privileges of the logged-in user. Affected versions include InCopy 21.3, 20.5.3, and earlier releases. The attack requires social engineering—convincing a user to open a malicious document—but once successful, the impact is severe.
- CVE-2026-34707HIGH 7.8
Adobe InCopy versions 21.3, 20.5.3 and earlier contain a memory safety flaw that allows attackers to execute arbitrary code on affected systems. The vulnerability is triggered when a user opens a specially crafted malicious file, making it a file-based attack vector that relies on social engineering or document distribution. The flaw exists in how InCopy handles memory allocation during file parsing, creating conditions where an attacker-controlled payload can overwrite adjacent heap memory and gain code execution privileges.
- CVE-2026-34708HIGH 7.8
Adobe InCopy versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow flaw that could allow an attacker to execute arbitrary code with the privileges of the user running the application. The vulnerability requires an attacker to trick a user into opening a specially crafted malicious file, making it a user-interaction-dependent threat. InCopy is Adobe's collaborative editing companion to InDesign, widely used in publishing and design workflows, so this affects organizations relying on these tools for content creation and layout work.
- CVE-2026-43724HIGH 7.8
A vulnerability in Apple's operating systems allows a malicious application to terminate the system unexpectedly or write data directly into kernel memory—the privileged core of the operating system. The flaw stems from insufficient validation of user-supplied input. An attacker would need to first gain the ability to run code on the target device, but once installed, the app requires no special permissions or user interaction to trigger the vulnerability. This is a serious local privilege escalation risk affecting iPhones, iPads, and Mac computers.
- CVE-2026-45175HIGH 7.8
Idira Endpoint Privilege Manager Agent (versions before 26.5) has a flaw in how it validates itself and enforces security rules. A local user on an affected system could exploit this weakness to bypass the agent's built-in protections and potentially execute actions that should be blocked. The vulnerability requires local access and authenticated login, but once exploited, could allow unauthorized operations at a high privilege level.
- CVE-2026-45176HIGH 7.8
Idira Endpoint Privilege Manager Agent contains a flaw in how it controls access to high-privileged components. An attacker with a regular user account on the same system can manipulate how the agent communicates internally or intercept file operations to trick it into performing actions it shouldn't allow. This could let them gain elevated privileges and take unauthorized actions on the machine. The vulnerability affects versions before 26.5.
- CVE-2026-47908HIGH 7.8
Adobe Dreamweaver Desktop versions 21.7 and earlier contain a memory safety defect that could allow attackers to execute arbitrary code on a victim's computer. The vulnerability is triggered when a user opens a specially crafted file, making it a user-interaction-dependent attack. The flaw affects Windows and macOS systems running vulnerable Dreamweaver versions.
- CVE-2026-47911HIGH 7.8
Adobe Acrobat Reader contains a critical flaw that allows attackers to execute arbitrary code on a user's computer by tricking them into opening a specially crafted file. The vulnerability affects multiple recent versions across Windows and macOS systems. While the flaw requires user interaction—specifically opening a malicious PDF or document—the potential impact is severe, as successful exploitation grants the attacker the same privileges as the logged-in user.
- CVE-2026-47912HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory vulnerability that allows an attacker to execute arbitrary code on a victim's computer with the privileges of the logged-in user. The attack requires the victim to open a specially crafted malicious PDF file. Versions 24.001.30365, 26.001.21651, and earlier on Windows and macOS are affected. This is a serious flaw because it bypasses the application's normal security controls and gives attackers direct code execution capability.
- CVE-2026-47913HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory flaw that allows an attacker to execute arbitrary code if a user opens a specially crafted PDF file. The vulnerability affects Acrobat Reader version 24.001.30365, 26.001.21651 and earlier on both Windows and macOS. Because exploitation requires the victim to manually open a malicious document, this is not a wormable vulnerability, but it represents a meaningful risk in environments where users regularly receive files from untrusted sources.
- CVE-2026-47914HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory safety bug that allows attackers to execute arbitrary code on a victim's system. The vulnerability is triggered when a user opens a specially crafted PDF file, making it a file-based attack that relies entirely on social engineering or misdirection to succeed. Versions 24.001.30365, 26.001.21651, and earlier are vulnerable. Once exploited, an attacker gains the same privileges as the logged-in user, potentially enabling data theft, malware installation, or lateral movement within a network.
- CVE-2026-47915HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory vulnerability that allows attackers to execute arbitrary code with the privileges of the user running the application. The flaw affects Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier on Windows and macOS. An attacker must trick a user into opening a specially crafted malicious document for the vulnerability to be exploited. Once triggered, the attacker gains full control over the affected system, potentially allowing data theft, system compromise, or lateral movement within your network.
- CVE-2026-47916HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory defect that attackers can exploit to run arbitrary code with the same privileges as the user opening the file. The vulnerability affects multiple Acrobat Reader versions and requires an attacker to trick a user into opening a specially crafted malicious PDF or document. While the technical barrier to triggering the flaw is low, successful exploitation still depends on user action—someone must be convinced to open the dangerous file.
- CVE-2026-47917HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory defect that allows attackers to execute code with the same privileges as the user running the application. The vulnerability exists in versions 24.001.30365, 26.001.21651 and earlier on Windows and macOS systems. An attacker must trick a user into opening a specially crafted file to trigger the flaw, making this a file-based attack vector rather than a remote network vulnerability.
- CVE-2026-47918HIGH 7.8
Adobe Acrobat Reader contains a use-after-free vulnerability that allows attackers to execute arbitrary code on affected systems. The flaw requires a victim to open a malicious PDF or similar file, at which point the attacker's code runs with the same permissions as the user. Versions 24.001.30365, 26.001.21651, and earlier on Windows and macOS are vulnerable. This is a high-severity issue that should be prioritized for patching.
- CVE-2026-47919HIGH 7.8
Adobe Acrobat Reader contains a use-after-free flaw that allows an attacker to execute arbitrary code on a victim's computer. The attack requires the victim to open a specially crafted malicious PDF or document file. Once executed, the attacker gains the same privileges as the user running Acrobat Reader, potentially enabling data theft, system compromise, or further lateral movement.
- CVE-2026-47920HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory vulnerability that allows an attacker to execute arbitrary code with the privileges of the user opening a malicious PDF file. The vulnerability affects Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier on both Windows and macOS. Successful exploitation requires social engineering to convince a user to open a specially crafted document, but once opened, the attacker gains full code execution in that user's security context.
- CVE-2026-47921HIGH 7.8
Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a use-after-free memory vulnerability that allows attackers to execute arbitrary code with the privileges of the logged-in user. The attack requires social engineering—a victim must be tricked into opening a malicious PDF or related file. This is a practical threat because Acrobat Reader is ubiquitous in enterprise and consumer environments, and users routinely open files from untrusted sources.
- CVE-2026-47952HIGH 7.8
Adobe Acrobat Reader contains a memory safety flaw that allows attackers to execute arbitrary code on a victim's computer when a malicious PDF or related document is opened. The vulnerability affects multiple versions across Windows and macOS platforms. While exploitation requires a user to be tricked into opening a specially crafted file, the impact is severe—an attacker could gain complete control of the user's system, steal data, or install malware. This is a classic code execution risk in a ubiquitous document viewer, making it a meaningful concern for any organization with Acrobat users.
- CVE-2026-47955HIGH 7.8
A Use After Free flaw in Adobe Acrobat Reader allows an attacker to execute arbitrary code on a victim's computer. The vulnerability exists in specific versions of Reader (24.001.30365, 26.001.21651 and earlier) and requires the victim to open a specially crafted malicious file. Once exploited, the attacker gains the same privileges as the user running the application, potentially allowing them to steal data, install malware, or modify documents.
- CVE-2026-47959HIGH 7.8
Adobe Acrobat Reader contains a flaw in how it processes certain file content that can cause the application to crash or allow an attacker to run arbitrary code with the same permissions as the user viewing the file. The vulnerability exists in versions 24.001.30365, 26.001.21651, and earlier across Windows and macOS. An attacker would need to trick a user into opening a specially crafted PDF or related document file to exploit this issue.
- CVE-2026-47965HIGH 7.8
Adobe Reader contains a critical flaw that allows attackers to run malicious code on a victim's computer if the user opens a specially crafted file. The vulnerability exists in versions 24.001.30365 and 26.001.21651 of Acrobat Reader and earlier releases. While the attacker cannot exploit this remotely—the victim must actively open the malicious file—successful exploitation grants the attacker the same permissions as the logged-in user, potentially enabling data theft, system compromise, or further lateral movement.