By vendor
Apple vulnerabilities
Known CVEs affecting Apple products, prioritized by severity, with SEC.co remediation and detection guidance.
712 published vulnerabilities · page 6 of 8
- CVE-2026-43699MEDIUM 6.5
A use-after-free memory vulnerability affects Apple's Safari browser and iOS/iPadOS/macOS platforms. An attacker can craft malicious web content that, when processed by a vulnerable browser, causes unexpected crashes. The vulnerability requires user interaction—specifically, visiting a malicious website—but does not enable data theft or system compromise beyond denial of service. Apple has released patched versions addressing the underlying memory management flaw.
- CVE-2026-43700MEDIUM 6.5
Apple has patched a cross-origin security issue affecting Safari and multiple Apple operating systems. The vulnerability allows attackers to craft malicious web content that, when visited by a user, can leak sensitive information by bypassing browser security controls that normally isolate websites from each other. The flaw was in how the browser tracked which origin (website) was responsible for data, making it possible to exfiltrate user data without the victim's knowledge beyond visiting a compromised or attacker-controlled page.
- CVE-2026-43703MEDIUM 6.5
CVE-2026-43703 is a memory handling flaw in Apple's operating systems that can cause an application to crash when processing specially crafted web content. An attacker would need to trick a user into visiting a malicious website or viewing attacker-controlled web content; the crash itself does not expose data or allow unauthorized access, but it does disrupt availability. Apple has patched this issue across iOS, iPadOS, macOS variants, tvOS, visionOS, and watchOS.
- CVE-2026-43706MEDIUM 6.5
Apple released security updates to fix a double free memory vulnerability affecting iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw could crash applications when users interact with specially crafted web content, but does not enable data theft or system compromise. This is a medium-severity availability issue requiring user interaction to trigger.
- CVE-2026-43707MEDIUM 6.5
Apple has patched a memory corruption vulnerability affecting Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. An attacker can craft a malicious web page that, when visited, crashes the affected application. The vulnerability requires user interaction—specifically, visiting a compromised or attacker-controlled website—but poses no risk of data theft or system compromise beyond the denial of service from the crash itself.
- CVE-2026-43709MEDIUM 6.5
Apple has patched a use-after-free memory vulnerability in Safari and multiple operating systems that could crash applications when processing malicious web content. An attacker would need to trick a user into visiting a crafted website, but no user interaction beyond standard browsing is required to trigger the crash. The vulnerability does not enable data theft or system compromise—only denial of service through application termination.
- CVE-2026-43712MEDIUM 6.5
A memory handling flaw in Safari and related Apple platforms can cause a web browser to crash when processing specially crafted web content. An attacker would need to trick a user into visiting a malicious website, but no special access or user privileges are required beyond normal browsing. The issue affects Safari on macOS and iOS/iPadOS devices, as well as Apple TV, Vision Pro, and Watch.
- CVE-2026-43713MEDIUM 6.5
Apple has patched a permissions flaw that could allow website visits to leak sensitive user data. The vulnerability affects Safari, iOS, iPadOS, and macOS. An attacker does not need special privileges—only the ability to host a website and trick a user into visiting it. Once a victim lands on the malicious page, the flaw can expose confidential information. The fix involves tightening permission checks to prevent unauthorized data access.
- CVE-2026-43716MEDIUM 6.5
A memory handling flaw in Apple's Safari browser and related Apple platforms can crash the browser when processing specially crafted web content. An attacker would need to trick a user into visiting a malicious website; the crash itself does not enable data theft or system compromise, but it does disrupt service. Apple has released patches addressing the underlying memory issue across Safari, iOS, iPadOS, and macOS.
- CVE-2026-43717MEDIUM 6.5
A use-after-free memory vulnerability exists in Apple's Safari browser and related operating systems. An attacker can craft a malicious webpage that, when visited, causes Safari to crash unexpectedly. The vulnerability does not enable data theft or system compromise—it is limited to availability impact (denial of service via crash). Exploitation requires user interaction: the victim must visit or be directed to the malicious web content.
- CVE-2026-43718MEDIUM 6.5
Apple has patched a stack overflow vulnerability affecting Safari and multiple Apple operating systems. The flaw occurs when processing specially crafted web content and can cause Safari to crash unexpectedly. While the vulnerability requires user interaction (visiting a malicious website), it affects a widely-used browser on billions of devices. Apple addressed it through improved input validation in Safari 26.5.2 and corresponding OS updates across iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS.
- CVE-2026-43720MEDIUM 6.5
A use-after-free memory vulnerability in Apple Safari and related systems allows attackers to crash Safari by tricking users into viewing specially crafted web content. The flaw stems from improper memory management that leaves dangling references to freed memory, which attackers can exploit to trigger an unexpected application crash. While the vulnerability requires user interaction (visiting a malicious website), it affects a widely used browser across multiple Apple platforms.
- CVE-2026-43721MEDIUM 6.5
CVE-2026-43721 is a clipboard hijacking vulnerability affecting Apple's Safari browser and iOS/iPadOS/macOS platforms. A malicious website can silently read clipboard data without user knowledge or consent. The flaw stems from insufficient state management in how browsers track clipboard access permissions. While the attack requires user interaction to visit a malicious site, it poses a meaningful risk to sensitive data that users routinely copy and paste, such as passwords, authentication tokens, or private information.
- CVE-2026-43726MEDIUM 6.5
A use-after-free memory vulnerability in Apple's Safari browser and related operating systems can cause unexpected application crashes when processing maliciously crafted web content. An attacker would need to convince a user to visit a malicious website, but no special privileges or complex setup is required for exploitation. The impact is limited to denial of service through crashes; the vulnerability does not enable data theft or system compromise.
- CVE-2026-43727MEDIUM 6.5
A use-after-free memory flaw in Apple's Safari browser and related operating systems can crash Safari when processing malicious web content. An attacker would need to trick a user into visiting a crafted webpage, but no authentication or special user privileges are required—standard web browsing is the attack vector. The crash causes a denial of service; there is no evidence of data theft or system compromise from this vulnerability alone.
- CVE-2026-43732MEDIUM 6.5
A path handling flaw in Apple's Safari browser and related operating systems could allow an attacker to trick users into visiting a malicious website that discloses sensitive information stored on their device. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted page—but does not allow attackers to modify data or crash systems. Apple has patched this across Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
- CVE-2026-43734MEDIUM 6.5
A use-after-free memory vulnerability affects Apple's Safari browser and iOS/iPadOS/macOS operating systems. An attacker can craft a malicious webpage that, when visited, causes Safari or the built-in web rendering engine to crash unexpectedly. While the crash itself denies service rather than enabling data theft or system compromise, the vulnerability requires user interaction—the person must visit the malicious site. Apple has issued patches across multiple platforms and device types.
- CVE-2026-43740MEDIUM 6.5
Apple has patched a memory disclosure vulnerability affecting Safari, iOS, iPadOS, and macOS. When a user visits a maliciously crafted website, the browser can leak sensitive data from its process memory to an attacker. The flaw stems from insufficient memory handling in the browser's web content processing engine. While the vulnerability requires user interaction (visiting a malicious site), the confidentiality risk is significant enough that Apple classified it as MEDIUM severity and issued fixes across multiple platforms simultaneously.
- CVE-2026-43742MEDIUM 6.5
CVE-2026-43742 is a use-after-free memory vulnerability in Apple's Safari browser and related operating systems. An attacker can craft a malicious website that, when visited by a user, causes Safari or the affected system to crash unexpectedly. The vulnerability requires user interaction (visiting a malicious site) but does not enable data theft or system compromise—it simply stops the browser or app from working. Apple has released patches across its ecosystem to fix the underlying memory management flaw.
- CVE-2026-43745MEDIUM 6.5
Safari and related Apple products contain an out-of-bounds write vulnerability that can crash the browser when processing specially crafted web content. An attacker would need to trick a user into visiting a malicious website to trigger the flaw. There is no indication of data theft or system compromise, but the denial-of-service impact may disrupt work or enable follow-on attacks.
- CVE-2026-43746MEDIUM 6.5
Safari and related Apple operating systems contain a use-after-free memory flaw that can crash the browser when processing specially crafted web content. An attacker would need to trick a user into visiting a malicious webpage, but no special privileges or system access are required. The crash itself does not allow data theft or system compromise—it is a denial-of-service issue. Apple has released patches for Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 that fix the underlying memory management problem.
- CVE-2026-9258MEDIUM 6.5
Canon's EOS Network Setting Tool versions 1.5.0 and earlier fail to properly validate SSH host keys during network connections. This allows an attacker positioned to intercept network traffic—such as on a shared Wi-Fi network or compromised router—to impersonate a legitimate server without the user's knowledge. If successful, the attacker can eavesdrop on sensitive configuration data exchanged between the tool and the camera system, such as network credentials or camera settings. The vulnerability requires user interaction (the tool must be actively used to connect), but the bar for exploitation is low given the prevalence of unencrypted or poorly-secured network environments.
- CVE-2026-9259MEDIUM 6.5
Canon EOS Network Setting Tool version 1.5.0 and earlier fails to properly validate SSL/TLS certificates when communicating with servers. This means an attacker positioned to intercept network traffic—such as on a shared Wi-Fi network or through a compromised router—could impersonate a legitimate Canon server and intercept sensitive data sent by the tool without the user noticing the certificate is invalid. The vulnerability requires user interaction to trigger (the tool must be actively used), but does not require special privileges. It affects Windows and macOS systems running the vulnerable tool.
- CVE-2026-9262MEDIUM 6.5
Canon EOS Network Setting Tool versions 1.5.0 and earlier use an insecure FTP protocol by default when configuring network settings for Canon EOS cameras. An attacker positioned on the same network could intercept the unencrypted FTP connection to capture sensitive credentials or modify camera configuration data in transit. This affects both Windows and macOS users of the tool.
- CVE-2026-9882MEDIUM 6.5
CVE-2026-9882 is a memory safety flaw in the ANGLE graphics library used by Google Chrome that allows attackers to steal data from websites you're visiting, provided they trick you into viewing a specially crafted web page. The vulnerability stems from an integer overflow—a programming error where a number wraps around unexpectedly—enabling unauthorized cross-origin data leakage. While the Chromium team rated this as "Critical," the CVSS base score of 6.5 reflects that successful exploitation requires user interaction (clicking or viewing content) and doesn't enable code execution or system-level damage. The flaw affects Chrome on Windows, macOS, and Linux systems.
- CVE-2026-9953MEDIUM 6.5
CVE-2026-9953 is a memory safety bug in the ANGLE graphics library used by Google Chrome that allows an attacker to read sensitive data from the browser process. An attacker can craft a malicious HTML page that, when visited by a user, exploits an out-of-bounds read to leak information like passwords, session tokens, or other confidential data stored in Chrome's memory. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require special privileges and works across Windows, macOS, and Linux. Google has assigned it high severity within Chromium's security framework.
- CVE-2026-9981MEDIUM 6.5
A flaw in the Skia graphics rendering library within Google Chrome allows attackers to trick users into visiting malicious web pages that expose sensitive data from the browser's memory. The vulnerability requires user interaction (clicking a link or visiting a site) but needs no special privileges to exploit, making it a realistic threat to everyday Chrome users.
- CVE-2026-9996MEDIUM 6.5
A flaw in Google Chrome's WebRTC component allows a remote attacker to trick a user into visiting a malicious webpage that reads sensitive data from the browser's memory. The vulnerability affects Mac users running Chrome versions before 148.0.7778.216. No user action beyond visiting a crafted page is required for the attacker to attempt exploitation.
- CVE-2026-11181MEDIUM 6.3
Google Chrome versions before 149.0.7827.53 contain a flaw in how the Media Session feature is implemented. An attacker can craft a malicious HTML page that, when visited by a user, bypasses the browser's same-origin policy—a fundamental security boundary that prevents websites from accessing data or functionality from other sites without permission. This could allow the attacker to read sensitive information, make unauthorized changes, or disrupt functionality within the context of other websites the user has open. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require any special browser configuration.
- CVE-2026-11184MEDIUM 6.3
Google Chrome versions before 149.0.7827.53 contain a flaw that allows attackers to bypass navigation controls through a specially crafted webpage. An attacker could craft a malicious HTML page that, when visited by a user, circumvents Chrome's built-in protections that normally restrict where the browser can navigate. This requires user interaction—the victim must visit the malicious page—but the barrier to exploitation is otherwise low. The vulnerability affects Chrome on Windows, macOS, and Linux systems.
- CVE-2026-11187MEDIUM 6.3
Google Chrome versions prior to 149.0.7827.53 contain a flaw in the Glic component that allows an attacker to bypass navigation restrictions by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or visiting the malicious page) and affects users across Windows, macOS, and Linux platforms. While the immediate impact is moderate, the ability to circumvent navigation safeguards could enable follow-on attacks or unauthorized content access.
- CVE-2026-11308MEDIUM 6.3
CVE-2026-11308 is a privilege escalation vulnerability in Google Chrome's extension system that allows an attacker to gain elevated permissions on a user's system. The attack requires social engineering—convincing a user to install a malicious browser extension—but once installed, the flaw in how Chrome enforces extension permissions allows the attacker to break out of the extension sandbox and perform actions at a higher privilege level than the extension should be allowed. This affects Windows, macOS, and Linux systems running Chrome versions prior to 149.0.7827.53.
- CVE-2026-47909MEDIUM 6.3
Dreamweaver Desktop versions 21.7 and earlier contain a flaw that allows attackers to read files from your computer that they shouldn't be able to access. The vulnerability requires social engineering—an attacker must trick you into opening a malicious file. Once opened, the attacker gains read access to sensitive data outside the application's normal boundaries. This is a local attack that doesn't require special permissions, but it does depend on user action.
- CVE-2026-47910MEDIUM 6.3
Dreamweaver Desktop versions 21.7 and earlier contain an authorization flaw that allows attackers to read files from your computer that they shouldn't have access to. The attacker must trick you into opening a malicious file, but once you do, they can potentially access sensitive documents and system files. This is a local attack that doesn't require special permissions to execute.
- CVE-2026-9989MEDIUM 6.3
Google Chrome contained a flaw in how it handles media files that allowed attackers to bypass the same-origin policy—a critical browser security boundary. An attacker could craft a malicious video file that, when opened by a user in Chrome, would enable unauthorized access to sensitive data from other websites the user was visiting. The vulnerability requires user interaction (clicking a link or opening a file) but does not require special privileges or complex attack setup.
- CVE-2026-45491MEDIUM 6.2
A flaw in .NET's file handling allows an attacker with local access to manipulate files through improper link resolution. The vulnerability stems from the system failing to properly validate symbolic links or similar path references before opening files, which means an attacker could redirect file operations to unintended targets. While this requires local access and does not compromise confidentiality, it can lead to unauthorized modification of sensitive data or system files.
- CVE-2026-9260MEDIUM 6.2
Canon EOS Network Setting Tool version 1.5.0 and earlier contains hard-coded cryptographic keys that are embedded directly in the application binary. An attacker with local access to an affected system can extract these keys and use them to decrypt or forge network communications intended to be protected by encryption. This is a confidentiality risk that does not require user interaction to exploit.
- CVE-2026-10916MEDIUM 6.1
CVE-2026-10916 is a cross-site scripting vulnerability in Google Chrome's developer tools that allows an attacker to inject malicious scripts or HTML content into a webpage. The attack requires two conditions: first, the attacker must have already compromised Chrome's renderer process (the component that executes web content), and second, the user must be tricked into visiting a specially crafted HTML page. While the initial compromise is a significant prerequisite, once achieved, this vulnerability enables the attacker to execute arbitrary code with the privileges of the browser session, potentially stealing sensitive data or performing actions on behalf of the user.
- CVE-2026-11122MEDIUM 6.1
Google Chrome versions before 149.0.7827.53 contain a flaw in how the keyboard input handler processes certain HTML page elements. An attacker can craft a malicious webpage that, when visited by an unsuspecting user, injects arbitrary scripts or HTML content that executes in a security context where it shouldn't be allowed—a technique called Uniform Cross-Site Scripting (UXSS). This bypasses the browser's same-origin policy protections that normally prevent cross-domain attacks. The vulnerability requires user interaction (clicking or viewing the page) but affects all major platforms where Chrome runs.
- CVE-2026-11150MEDIUM 6.1
Google Chrome versions prior to 149.0.7827.53 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious webpage that, when visited, injects arbitrary scripts or HTML content that execute in the context of unrelated sites (a technique known as Universal Cross-Site Scripting or UXSS). This bypasses the same-origin policy that normally prevents one site from accessing data or performing actions on another. The vulnerability requires user interaction—a victim must visit the attacker's page—but does not require any special browser configuration or user privileges to trigger.
- CVE-2026-11186MEDIUM 6.1
Google Chrome versions prior to 149.0.7827.53 contain a vulnerability in CSS handling that allows attackers to inject malicious scripts or HTML into web pages users visit. An attacker would craft a specially designed webpage that, when opened in a vulnerable version of Chrome, bypasses security boundaries and executes unauthorized code in the context of other websites. This type of attack, known as Universal XSS (UXSS), is particularly dangerous because it affects the browser itself rather than individual websites, potentially compromising user data across multiple domains.
- CVE-2026-11205MEDIUM 6.1
Google Chrome on iOS versions prior to 149.0.7827.53 contain a vulnerability that allows attackers to inject malicious scripts or HTML into web pages through crafted QR codes. The attack requires user interaction—specifically, the victim must engage with certain UI gestures in response to the attacker's QR code—but once triggered, the injected content runs with the privileges of the page being viewed. This is a cross-origin scripting (UXSS) issue, meaning the injected code can affect pages from different origins, potentially stealing session cookies, credentials, or sensitive data.
- CVE-2026-11229MEDIUM 6.1
Google Chrome versions before 149.0.7827.53 contain a flaw in how the application handles certain enterprise features that could allow someone with physical access to your device to gain elevated privileges. The vulnerability requires an attacker to be present at the machine itself and does not need you to take any action—they can exploit it directly. This is a local-only threat and cannot be exploited remotely over the internet.
- CVE-2026-11273MEDIUM 6.1
Google Chrome versions before 149.0.7827.53 contain a vulnerability in the Omnibox (the address/search bar) that fails to properly validate user input. An attacker can craft a malicious HTML page that, when visited by a user who interacts with the Omnibox through specific UI actions, allows injection of arbitrary scripts or HTML content. This is a cross-site scripting variant (UXSS) that bypasses the normal security boundary between web pages. The attack requires user interaction and social engineering to be effective, but once triggered, can compromise the integrity and confidentiality of the browsing session.
- CVE-2026-12459MEDIUM 6.1
Google Chrome versions prior to 149.0.7827.155 contain a vulnerability in the Serial component that allows attackers to inject malicious scripts or HTML into web pages through a specially crafted HTML file. The attack requires user interaction (clicking or otherwise engaging with the malicious page) but does not require the victim to have special privileges. The injected content can compromise page integrity and access sensitive user data within the affected browser context.
- CVE-2026-14068MEDIUM 6.1
Google Chrome on iOS contains a flaw in how it handles the Omnibox (address bar) that can allow an attacker to inject malicious scripts or HTML content into a webpage you're viewing. The vulnerability requires a user to perform specific gestures in the browser interface—such as interacting with the address bar in a particular way—after visiting a specially crafted webpage. This is a cross-site scripting variant (UXSS) that affects Chrome versions before 150.0.7871.47 on iOS devices.
- CVE-2026-57257MEDIUM 6.1
CVE-2026-57257 is a memory safety flaw in Foxit PDF Editor and Reader that crashes the application when processing a specially crafted PDF file. The vulnerability stems from insufficient validation of entity indices during PRC (a PDF internal format) parsing, allowing an attacker to read memory beyond array boundaries. When a user opens a malicious PDF, the application crashes due to an out-of-bounds read, resulting in a denial of service. This is a local attack that requires user interaction—the victim must open the malicious file.
- CVE-2026-57258MEDIUM 6.1
A vulnerability in PRC file parsing affects Foxit PDF Editor and Reader, as well as certain Windows and macOS systems. The issue stems from unsafe handling of file structure metadata: when a PRC file is opened, the application trusts the header information describing the file's array layout without validating it. An attacker can craft a malicious PRC file with misleading structure data that causes the application to read beyond allocated memory boundaries. This leads to crashes and potential information disclosure. User interaction is required—the victim must open the specially crafted file.
- CVE-2026-0277MEDIUM 5.9
CVE-2026-0277 is a certificate validation flaw in Palo Alto Networks' Prisma Access Agent for iOS that allows an attacker positioned on the network to intercept and potentially manipulate VPN traffic. Because the iOS agent fails to properly validate SSL/TLS certificates, an attacker can impersonate legitimate VPN endpoints and decrypt traffic, compromising the confidentiality of data meant to be protected by the VPN. The vulnerability requires network positioning (such as on a shared Wi-Fi network or compromised network infrastructure) but no user interaction or authentication. Windows, macOS, Linux, Android, and ChromeOS variants of the Prisma Access Agent are not vulnerable.
- CVE-2026-11199MEDIUM 5.9
Google Chrome versions before 149.0.7827.53 contain a flaw in how WebRTC handles network traffic that could allow an attacker positioned on the same network to steal sensitive information across website boundaries. The vulnerability requires the attacker to be in a privileged network position—such as on a shared Wi-Fi network or controlling network infrastructure—but does not require user interaction or special permissions. The risk is limited to information disclosure; the flaw cannot be used to modify data or crash the browser.
- CVE-2026-11238MEDIUM 5.9
Google Chrome versions before 149.0.7827.53 contain a flaw in how DevTools handles extension interactions that could allow an attacker to extract sensitive data from process memory. The attack requires social engineering—convincing a user to install a malicious Chrome extension—but if successful, an attacker gains access to potentially confidential information stored in memory that the extension can observe. This is classified as a medium-severity issue despite Chromium's internal 'Low' rating, reflecting the real-world impact of memory disclosure combined with the user-interaction barrier.
- CVE-2026-9320MEDIUM 5.9
IBM WebSphere Application Server versions 9.0 and 8.5, along with WebSphere Liberty versions 17.0.0.3 through 26.0.0.6, contain a denial-of-service vulnerability triggered by specially-crafted network requests. An attacker can exploit this remotely without authentication to exhaust server memory, causing service degradation or outages. The vulnerability does not compromise confidentiality or integrity—its impact is purely on availability.
- CVE-2026-14063MEDIUM 5.7
CVE-2026-14063 is a memory disclosure vulnerability in Google Chrome's Chromecast component that allows a local attacker to read sensitive data from the browser process. The flaw requires the attacker to be on the same network and the user to interact with malicious network traffic, but does not require elevated privileges. While individual impact is modest, this type of information leak can enable reconnaissance for more sophisticated attacks. Google rated the underlying issue as low severity, but the combination of local network access, user interaction requirement, and memory disclosure capability warrants MEDIUM priority in most enterprise environments.
- CVE-2020-9711MEDIUM 5.5
Adobe Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier contain a flaw that allows an attacker to read sensitive data from a computer's memory when a user opens a specially crafted PDF file. The vulnerability does not allow attackers to modify files or crash the application, but it does expose information that should remain private. An attacker would need to trick someone into opening a malicious PDF to exploit this issue.
- CVE-2020-9713MEDIUM 5.5
CVE-2020-9713 is a memory disclosure vulnerability in Adobe Acrobat and Reader that allows an attacker to read sensitive data from a victim's computer. The flaw occurs when the application improperly accesses memory outside intended boundaries while processing a malicious PDF file. An attacker must trick a user into opening a crafted document to exploit it—there is no remote attack vector. While the vulnerability cannot directly crash the application or alter files, it can expose confidential information such as cached credentials, encryption keys, or other sensitive data resident in memory at the time of exploitation.
- CVE-2025-24165MEDIUM 5.5
A permissions enforcement gap in macOS allows applications to trigger unexpected system shutdowns. The vulnerability stems from insufficient access controls that permit an app—without requiring special privileges or admin credentials—to initiate a termination condition. Apple addressed this by reinforcing permission checks across the affected operating system versions. The attack requires user interaction (such as running or interacting with a malicious app), but does not require the user to have special knowledge of the vulnerability.
- CVE-2025-24268MEDIUM 5.5
CVE-2025-24268 is a medium-severity vulnerability in macOS that stems from inadequate validation of directory paths during parsing. An attacker with local access and user-level privileges could potentially exploit this weakness to read sensitive user data on an affected system. Apple has resolved this issue in macOS Sequoia 15.4 by implementing stricter path validation controls.
- CVE-2025-30431MEDIUM 5.5
CVE-2025-30431 is a medium-severity vulnerability in Apple macOS that allows a malicious application already running on a user's computer to access private information. The flaw stems from inadequate validation checks in the operating system. Because an attacker must first get a malicious app onto the system and have it execute with user-level privileges, the real-world risk depends heavily on how the app gets installed—whether through social engineering, supply-chain compromise, or user mistake. Apple has patched this across three recent macOS versions.
- CVE-2025-30459MEDIUM 5.5
CVE-2025-30459 is a privacy vulnerability affecting macOS that could allow an app to access sensitive user data without appropriate restrictions. Apple addressed this by removing the vulnerable code path in macOS Sequoia 15.4. The issue requires local access and an already-installed application to exploit, limiting its immediate risk to targeted or supply-chain scenarios.
- CVE-2025-43278MEDIUM 5.5
CVE-2025-43278 is a local privilege escalation vulnerability in macOS Sequoia that allows an application to access protected user data through improper symlink handling. An attacker with local access and user interaction can exploit this to read sensitive files that should be restricted. The vulnerability requires the user to take an action (such as opening a file or interacting with an app), but does not require administrator privileges. Apple has addressed this in macOS Sequoia 15.4 with improved symlink validation logic.
- CVE-2025-43339MEDIUM 5.5
A sandbox isolation weakness in macOS Tahoe allows a malicious app running with user privileges to read sensitive user data that should have been protected. The vulnerability does not allow the attacker to modify data or crash the system, only to view it. Apple has patched this in macOS Tahoe 26.1 by strengthening sandbox restrictions.
- CVE-2025-46293MEDIUM 5.5
CVE-2025-46293 is a local privilege escalation vulnerability in macOS that allows installed applications to read protected user data through improper symlink handling. An attacker with local access and the ability to run an app on the target system could potentially bypass file access restrictions and view sensitive files. The vulnerability requires local presence and user-level privileges to exploit, making it a concern primarily for multi-user systems or scenarios where an attacker can install malicious software. Apple has resolved this with improved symlink validation in macOS Sequoia 15.4.
- CVE-2025-46313MEDIUM 5.5
CVE-2025-46313 is a logging defect in macOS Tahoe that could allow a third-party application to access sensitive user information that should have been redacted from system logs. The vulnerability stems from incomplete data redaction in logging routines, enabling an app to read information it should not have access to. This is a local attack vector requiring user interaction, such as installing or running the vulnerable application.
- CVE-2026-12444MEDIUM 5.5
A memory reading vulnerability exists in Google Chrome's Chromoting feature (Google's remote desktop tool) on Windows systems running versions prior to 149.0.7827.155. An attacker with local access to a machine can craft a malicious file that, when interacted with by a user, causes Chrome to read data outside its intended memory boundaries. This out-of-bounds read could expose sensitive information already present in the process's memory—such as cached authentication tokens, encryption keys, or other confidential data—without requiring elevated privileges or special system access. The vulnerability is not currently known to be exploited in the wild.
- CVE-2026-13914MEDIUM 5.5
Google Chrome on macOS contains a vulnerability in its password handling that could allow a local attacker to read sensitive data from the browser's memory if the user interacts with a specially crafted file. The vulnerability affects Chrome versions before 150.0.7871.47 on Mac systems. An attacker would need local access to the affected system and require user interaction to trigger the vulnerability, but no special privileges are needed to exploit it.
- CVE-2026-34657MEDIUM 5.5
CAI Content Credentials, a library used to manage and verify digital content authenticity, contains a path traversal flaw in versions [email protected], c2pa-v0.80.1 and earlier. The vulnerability allows an attacker to write files to arbitrary locations on a system by crafting a malicious archive that, when extracted by a user, exploits insufficient pathname validation. This is a local attack requiring user interaction—an end user must actively extract or open the malicious file for the attack to succeed.
- CVE-2026-34703MEDIUM 5.5
A flaw in Adobe InDesign versions 21.3, 20.5.3 and earlier can cause the application to crash when a user opens a specially crafted malicious file. The vulnerability stems from improper handling of null pointer references in memory, which an attacker could weaponize by distributing a booby-trapped document. While this doesn't allow an attacker to steal data or take control of your system, it does enable denial-of-service attacks that interrupt work and productivity.
- CVE-2026-34704MEDIUM 5.5
InDesign Desktop has a vulnerability that causes the application to crash when a user opens a specially crafted malicious file. While the crash itself doesn't expose data or allow an attacker to take control of the system, it does disrupt work by forcing the application to shut down unexpectedly. Versions 21.3, 20.5.3, and earlier are affected. An attacker must trick someone into opening the malicious file—the vulnerability does not spread on its own or affect systems remotely.
- CVE-2026-34705MEDIUM 5.5
Adobe InDesign has a memory-reading vulnerability that can expose sensitive data stored in the application's working memory. When a user opens a specially crafted file, the vulnerability allows an attacker to read beyond the intended boundaries of memory, potentially revealing passwords, encryption keys, or other confidential information. This is a local attack that requires user interaction—the victim must be tricked into opening a malicious file. The vulnerability affects InDesign versions 21.3, 20.5.3, and earlier on both Windows and macOS systems.
- CVE-2026-43722MEDIUM 5.5
A vulnerability in Apple's operating systems allows apps running on a device to access sensitive information stored in the kernel—the core of the operating system. An attacker would need to already have an app installed on the target device to exploit this issue. The vulnerability stems from insufficient validation of user-supplied input before the kernel processes it. Apple has patched this across iPhone, iPad, and Mac by improving how the system sanitizes input data.
- CVE-2026-47923MEDIUM 5.5
Adobe Acrobat Reader contains a flaw that allows an attacker to read sensitive data from a user's computer memory by tricking them into opening a specially crafted file. The vulnerability doesn't damage files or prevent the application from running, but it could expose confidential information like passwords, encryption keys, or personal data that happens to be in memory at the time of exploitation. Versions 24.001.30365, 26.001.21651 and earlier on Windows and macOS are affected.
- CVE-2026-47924MEDIUM 5.5
Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a use-after-free memory flaw that could allow an attacker to read sensitive data from the application's memory. The vulnerability requires a user to open a crafted malicious PDF or document file, making this a low-friction attack that relies on social engineering rather than complex exploitation techniques. While memory disclosure alone does not enable direct system compromise, the leaked information could include credentials, encryption keys, or other confidential content.
- CVE-2026-47925MEDIUM 5.5
Adobe Acrobat Reader contains an integer overflow flaw that crashes the application when a user opens a specially crafted file. While this is a denial-of-service issue rather than a data breach or code execution vulnerability, it can disrupt business workflows. The flaw affects Acrobat Reader DC versions 24.001.30365, 26.001.21651 and earlier across Windows and macOS. An attacker must trick a user into opening a malicious PDF or document to trigger the crash.
- CVE-2026-47926MEDIUM 5.5
Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a memory reading flaw that allows attackers to extract sensitive information from your system. The vulnerability requires a user to open a specially crafted malicious file, making social engineering a necessary component of any attack. While the flaw cannot be used to modify files or crash the application, the potential for exposing confidential data—such as encryption keys, credentials, or personal information resident in memory—presents a meaningful risk to organizations handling sensitive documents.
- CVE-2026-47961MEDIUM 5.5
Adobe Acrobat Reader contains an out-of-bounds read flaw that allows attackers to extract sensitive data from system memory. The vulnerability requires user interaction—specifically, opening a malicious PDF or document file. When triggered, the flaw exposes unintended memory contents that could include confidential information resident in the application's process space.
- CVE-2026-11157MEDIUM 5.4
A script injection vulnerability in Google Chrome's accessibility features allows attackers to inject arbitrary scripts and HTML into web pages if a user installs a malicious extension. The vulnerability, tracked as CVE-2026-11157, requires user interaction (installing an extension) to exploit, making it a social engineering vector rather than a network-based attack. Chrome versions before 149.0.7827.53 are affected.
- CVE-2026-11232MEDIUM 5.4
Google Chrome versions before 149.0.7827.53 contain a flaw in how the TabGroups feature handles network input, allowing attackers to deceive users through fake or misleading visual elements in the browser interface. An attacker would need to trick a user into visiting a malicious website or intercepting network traffic, but the actual attack surface is relatively narrow—the vulnerability requires user interaction and does not enable data theft or system crashes on its own.
- CVE-2026-11243MEDIUM 5.4
Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles downloads that allows an attacker to bypass navigation restrictions by serving a specially crafted web page. When a user visits the malicious page, the browser's normal safeguards that prevent unwanted navigation can be circumvented, potentially allowing redirection to unintended destinations or other restricted actions. The vulnerability requires user interaction (clicking or visiting a page) and affects Chrome on Windows, macOS, and Linux.
- CVE-2026-11666MEDIUM 5.4
Google Chrome versions prior to 149.0.7827.103 contain a flaw where the browser fails to properly validate user-supplied input in certain UI elements. An attacker can exploit this by crafting a malicious HTML page that, when visited, displays fake browser UI components or dialogs—a technique known as UI spoofing. This could trick users into believing they're interacting with legitimate Chrome interface elements, potentially leading to credential theft, social engineering attacks, or other user-directed compromise. The vulnerability requires user interaction (visiting the crafted page) but no special privileges, making it a concern for general web browsing.
- CVE-2026-11701MEDIUM 5.4
Google Chrome versions before 149.0.7827.103 contain a flaw in how the Guest View feature handles crafted HTML pages, allowing attackers to trick users with fake or misleading interface elements. An attacker would need to host a malicious webpage and convince a user to visit it while Chrome's Guest View is active. The vulnerability does not allow data theft or system compromise on its own, but the spoofed interface could be used to deceive users into taking actions they wouldn't otherwise take.
- CVE-2026-9971MEDIUM 5.4
A vulnerability in Google Chrome on iOS allows attackers to inject malicious scripts or HTML code into web pages when a user performs specific interactions with the browser. An attacker would need to craft a deceptive webpage and convince a user to engage with it in particular ways—such as specific taps or gestures—to trigger the injection. Once successful, the attacker gains the ability to run arbitrary code in the context of the webpage, potentially stealing data or modifying what the user sees.
- CVE-2025-46308MEDIUM 5.3
Apple has addressed an authorization flaw affecting iOS, iPadOS, and macOS that could allow installed apps to access sensitive user information without proper permission checks. The vulnerability stems from inadequate state management in the platform's authorization framework. While the issue requires a malicious or compromised app to be present on a device, the potential for information disclosure makes this a meaningful security concern for users managing sensitive data. This is not currently known to be exploited in the wild, but the low barrier to exploitation (no user interaction required, network accessible) warrants timely patching.
- CVE-2026-11004MEDIUM 5.3
CVE-2026-11004 is a memory disclosure vulnerability in Google Chrome's ANGLE graphics library. An attacker who has already compromised Chrome's renderer process can craft a malicious HTML page to read sensitive data from the browser's memory. While this requires prior compromise of the renderer, the ability to extract potentially sensitive information makes it a meaningful security concern for organizations running Chrome.
- CVE-2026-11098MEDIUM 5.3
Google Chrome versions prior to 149.0.7827.53 contain a flaw in GPU handling that allows an attacker with control of the renderer process to extract sensitive data from other websites. The vulnerability requires user interaction and a compromised renderer, making it a targeted risk rather than a mass-exploitation vector. The issue stems from insufficient validation when processing untrusted input, permitting cross-origin information disclosure.
- CVE-2026-11174MEDIUM 5.3
CVE-2026-11174 is a Site Isolation bypass vulnerability in Google Chrome that allows an attacker who has already compromised a browser's renderer process to read sensitive data from other websites. The flaw stems from improper implementation of Chrome's Site Isolation feature, a critical security boundary that normally prevents one website from accessing another's data. An attacker would need to first gain control of the renderer process—typically through a separate vulnerability—and then use a specially crafted HTML page to circumvent this protection. While the attack requires a prior compromise, the consequence of success is confidentiality loss across site boundaries.
- CVE-2026-11246MEDIUM 5.3
Google Chrome versions prior to 149.0.7827.53 contain a flaw in IndexedDB—a browser feature for storing data locally—that fails to properly validate user input. If an attacker compromises the renderer process (the part of Chrome that displays web pages), they can craft a malicious HTML page to bypass the same-origin policy, a critical security boundary that normally prevents one website from accessing another's data. This requires the attacker to already control the renderer process, which limits the immediate threat but remains a meaningful integrity risk.
- CVE-2026-11678MEDIUM 5.3
An integer overflow vulnerability exists in libyuv, an image processing library bundled with Google Chrome. The flaw allows an attacker who has already compromised Chrome's renderer process to read sensitive information from memory by serving a specially crafted HTML page. Because the attack requires prior renderer compromise, real-world exploitation involves a multi-stage attack chain rather than direct network exploitation.
- CVE-2026-12015MEDIUM 5.3
A use-after-free vulnerability in Google Chrome's autofill feature allows attackers who have already compromised the browser's renderer process to leak sensitive information from memory. An attacker would need to trick a user into visiting a specially crafted webpage while the renderer is in a vulnerable state. This is not a remote code execution risk on its own, but represents a significant information disclosure threat once an attacker has a foothold in the rendering engine.
- CVE-2026-12025MEDIUM 5.3
Google Chrome versions before 149.0.7827.115 contain a flaw in how the browser validates input within its Network component. An attacker who has already compromised Chrome's renderer process—the sandboxed environment that executes web content—can craft a malicious HTML page to leak sensitive data across security boundaries that normally prevent one website from accessing another's information. This is a privilege-escalation scenario: it requires the renderer to already be compromised, but then allows the attacker to exfiltrate data that should be protected by the browser's same-origin policy.
- CVE-2026-12033MEDIUM 5.3
Google Chrome versions prior to 149.0.7827.115 contain an out-of-bounds memory read vulnerability in the VideoCapture component. An attacker who has already compromised Chrome's GPU process can exploit this flaw by serving a specially crafted webpage, allowing them to read sensitive data from the process's memory. This is a post-compromise attack requiring prior GPU process compromise and user interaction.
- CVE-2026-13023MEDIUM 5.3
CVE-2026-13023 is a memory disclosure vulnerability in Google Chrome's GPU handling code. If an attacker has already compromised Chrome's renderer process—the sandboxed component that executes web content—they can craft a malicious HTML page to read uninitialized GPU memory, potentially exposing sensitive data from the browser's process memory. This requires two conditions: prior renderer compromise and user interaction with the malicious page. The vulnerability affects Chrome versions before 149.0.7827.197.
- CVE-2026-13874MEDIUM 5.3
A race condition exists in Google Chrome's DataTransfer mechanism that allows attackers to leak sensitive information from process memory. An attacker can craft a malicious HTML page that, when visited by a user, exploits timing vulnerabilities to read data that should be protected. While the attack requires user interaction (visiting a malicious website) and careful timing, the potential exposure of process memory contents makes this a meaningful privacy risk.
- CVE-2026-13877MEDIUM 5.3
A vulnerability in Google Chrome's ANGLE graphics library allows an attacker who has already gained control of the browser's renderer process to read sensitive data from the browser's memory by tricking a user into viewing a specially crafted webpage. The attacker cannot exploit this directly from the internet—they must first compromise the renderer, making this a secondary attack that increases the severity of other browser vulnerabilities. Chrome versions before 150.0.7871.47 are affected.
- CVE-2026-13890MEDIUM 5.3
A memory safety flaw in Google Chrome's Chromecast component allows an attacker who has already compromised the browser's renderer process to read sensitive data from process memory. The vulnerability requires user interaction (clicking a malicious link or visiting a crafted website) but does not lead to code execution or system crashes. Chrome versions prior to 150.0.7871.47 are affected across Windows, macOS, and Linux platforms.
- CVE-2026-13970MEDIUM 5.3
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the browser handles uninitialized memory in media processing. An attacker who has already compromised Chrome's renderer process—the component that interprets web content—can craft a malicious HTML page that leaks sensitive information from the browser's memory to the attacker. This is not a vulnerability that allows initial system compromise; it requires a prior breach of the renderer process, typically through another security flaw. Once that foothold exists, however, an attacker could extract passwords, authentication tokens, private keys, or other confidential data residing in memory.
- CVE-2026-13971MEDIUM 5.3
Google Chrome contains a memory safety issue in its Skia graphics library that could allow an attacker to leak sensitive information from the browser's renderer process. If an attacker first compromises the renderer (the part of Chrome that processes web content), they can craft a malicious web page that reads uninitialized memory—data left over from previous operations that shouldn't be accessible. This could expose passwords, session tokens, or other sensitive data. The vulnerability requires the attacker to already have compromised the renderer and requires user interaction to visit the malicious page, making it a secondary concern in most attack chains.
- CVE-2026-13975MEDIUM 5.3
A memory safety vulnerability exists in the ANGLE graphics library within Google Chrome on macOS that could allow an attacker to read sensitive data from Chrome's memory. The vulnerability requires two conditions: the attacker must first compromise Chrome's renderer process (the part that displays web content), and the user must visit a malicious web page. Once both conditions are met, an attacker could potentially extract sensitive information such as passwords, session tokens, or other data present in Chrome's memory at the time of exploitation.
- CVE-2026-14012MEDIUM 5.3
Google Chrome versions before 150.0.7871.47 contain a side-channel vulnerability in how the browser processes CSS that could allow an attacker to leak sensitive information from the browser process's memory. By crafting a malicious HTML page and tricking a user into viewing it, an attacker could potentially extract data that should remain private. The flaw is specific to how CSS rendering interacts with memory access patterns, creating a timing or behavioral difference that leaks information—a classic side-channel attack vector.
- CVE-2026-14049MEDIUM 5.3
Google Chrome contained a flaw in how it handled GPU operations that could allow an attacker to read sensitive data from memory. The attacker would need to first compromise Chrome's renderer process (the component that processes web page content) and then trick a user into visiting a malicious webpage. If successful, they could extract information that should have remained private. This issue affected Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-14112MEDIUM 5.3
Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser handles certain user interactions on web pages. An attacker who tricks a user into performing specific gestures (like clicking or dragging) on a malicious webpage can potentially read sensitive data from Chrome's memory. While the Chromium team rates this as low severity, the ability to extract process memory elevates the practical risk. The vulnerability requires active user participation—it cannot be exploited passively.