Early access — the directory is still filling out, and every rating here is a reported experience.

Security releases

Apple

macOS Tahoe 26.6

128067 Jul 27, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/128067. 153 CVE entries, 26 additional recognitions. Available for: macOS Tahoe. Draft — review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/128067
Are you credited here? Sign in and claim your line — it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

376 lines
Showing 251–300 of 376 · page 6 of 8
CVE-2026-43779 BR2026-0000-001113 Screen Sharing Server unclaimed
An app may be able to intercept network connections intended for another process
Credited as Asaf Cohen
CVE-2026-43777 BR2026-0000-001114 Screen Sharing Server unclaimed
A remote attacker may be able to cause a denial of service
Credited as Junming C.(Chapoly1305)
CVE-2026-43760 BR2026-0000-001115 Screen Sharing Server unclaimed
An app may be able to access user-sensitive data
Credited as Alfredo Pesoli (@__rev) of Bynar.io
CVE-2026-43760 BR2026-0000-001116 Screen Sharing Server unclaimed
An app may be able to access user-sensitive data
Credited as wdszzml
CVE-2026-43760 BR2026-0000-001117 Screen Sharing Server unclaimed
An app may be able to access user-sensitive data
Credited as Atuin Automated Vulnerability Discovery Engine
CVE-2026-43728 BR2026-0000-001118 Security unclaimed
An attacker may be able to modify the state of the Keychain
Credited as Bob Gendler of the National Institute of Standards and Technology
CVE-2026-43755 BR2026-0000-001119 SecurityAgent unclaimed
An app may be able to gain root privileges
Credited as Mickey Jin (@patch1t)
CVE-2026-64745 BR2026-0000-001120 Siri unclaimed
A person with physical access to a locked device may be able to access contacts and photos
Credited as Vivek Dhar
CVE-2026-64745 BR2026-0000-001121 Siri unclaimed
A person with physical access to a locked device may be able to access contacts and photos
Credited as ASI (RM) in Border Security Force
CVE-2026-64745 BR2026-0000-001122 Siri unclaimed
A person with physical access to a locked device may be able to access contacts and photos
Credited as FTR HQ BSF Kashmir
CVE-2026-43800 BR2026-0000-001123 Siri unclaimed
An app may be able to access sensitive user data
Credited as Stanislav Jelezoglo
CVE-2026-39873 BR2026-0000-001124 SMB unclaimed
Connecting to a malicious SMB server may lead to unexpected system termination
Credited as Peter Malone
CVE-2026-64696 BR2026-0000-001125 SMB unclaimed
A remote user may be able to cause unexpected system termination or corrupt kernel memory
Credited as Feng Xue
CVE-2026-64696 BR2026-0000-001126 SMB unclaimed
A remote user may be able to cause unexpected system termination or corrupt kernel memory
Credited as XGPT of ThreatBook
CVE-2026-64696 BR2026-0000-001127 SMB unclaimed
A remote user may be able to cause unexpected system termination or corrupt kernel memory
Credited as Peter Malone
CVE-2026-64704 BR2026-0000-001128 SMB unclaimed
An app may be able to cause unexpected system termination
Credited as Claudio Bozzato
CVE-2026-64704 BR2026-0000-001129 SMB unclaimed
An app may be able to cause unexpected system termination
Credited as Francesco Benvenuto of Cisco Talos
CVE-2026-64704 BR2026-0000-001130 SMB unclaimed
An app may be able to cause unexpected system termination
Credited as Aswin Kumar Gokulakannan
CVE-2026-64704 BR2026-0000-001131 SMB unclaimed
An app may be able to cause unexpected system termination
Credited as Kitten Food
CVE-2026-64704 BR2026-0000-001132 SMB unclaimed
An app may be able to cause unexpected system termination
Credited as Peter Malone
CVE-2026-64704 BR2026-0000-001133 SMB unclaimed
An app may be able to cause unexpected system termination
Credited as Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-43774 BR2026-0000-001134 Spotlight unclaimed
An app may be able to access sensitive user data
Credited as Csaba Fitzl (@theevilbit) of Iru
CVE-2026-43770 BR2026-0000-001135 StorageKit unclaimed
An app may be able to access sensitive user data
Credited as Tien-Chih Lin of CyCraft Technology
CVE-2026-43768 BR2026-0000-001136 udf unclaimed
An app may be able to cause unexpected system termination
Credited as Hyunwoo Kim (@v4bel)
CVE-2026-64703 BR2026-0000-001137 WebDAV unclaimed
An app may be able to cause a denial-of-service
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-64699 BR2026-0000-001138 WebDAV unclaimed
An app may be able to disclose kernel memory
Credited as Bruce Dang of Calif.io
CVE-2026-64713 BR2026-0000-001139 WebKit unclaimed
Websites may know if the user has visited a given link
Credited as Kwak Kiyong
CVE-2026-64713 BR2026-0000-001140 WebKit unclaimed
Websites may know if the user has visited a given link
Credited as Song Nuri
CVE-2026-64730 BR2026-0000-001141 WebKit unclaimed
Visiting a website that frames malicious content may lead to UI spoofing
Credited as Kagami Rosylight of Mozilla
CVE-2026-64783 BR2026-0000-001142 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as 杉山 壮太
CVE-2026-64783 BR2026-0000-001143 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as lattice
CVE-2026-64783 BR2026-0000-001144 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Behzad Najjarpour Jabbari (@_G4ru_)
CVE-2026-64783 BR2026-0000-001145 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Junyeong Lee
CVE-2026-64783 BR2026-0000-001146 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Mooth.ai
CVE-2026-64783 BR2026-0000-001147 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-64783 BR2026-0000-001148 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Using GLM From Z.AI
CVE-2026-64783 BR2026-0000-001149 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Gia Bui (@yabeow) from Calif.io
CVE-2026-64757 BR2026-0000-001150 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Milad Nasr
CVE-2026-64757 BR2026-0000-001151 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Nicholas Carlini with Claude
CVE-2026-64757 BR2026-0000-001152 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Anthropic
CVE-2026-43804 BR2026-0000-001153 WebKit unclaimed
Visiting a website may lead to an app denial-of-service
Credited as Heiko Kiesel of SEEMOO
CVE-2026-43804 BR2026-0000-001154 WebKit unclaimed
Visiting a website may lead to an app denial-of-service
Credited as TU Darmstadt
CVE-2026-43821 BR2026-0000-001155 WebKit unclaimed
An app may be able to read files outside of its sandbox
Credited as Brian Carpenter
CVE-2026-64718 BR2026-0000-001156 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-64719 BR2026-0000-001157 WebRTC unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Shaheen Fazim
CVE-2026-64726 BR2026-0000-001158 Wi-Fi unclaimed
An attacker in physical proximity may be able to corrupt process memory
Credited as Mathis Mansière
CVE-2026-64726 BR2026-0000-001159 Wi-Fi unclaimed
An attacker in physical proximity may be able to corrupt process memory
Credited as Peter Malone
CVE-2026-28932 BR2026-0000-001160 xar unclaimed
An app may be able to cause a denial of service
Credited as Mathis Mansière
Additional recognition BR2026-0000-001161 Audio unclaimed
Credited as Niels Hofmans
Additional recognition BR2026-0000-001162 copyfile unclaimed
Credited as Keisuke Hosoda