Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 25 March 2026

RSS

112 vulnerabilities published on 25 March 2026

Severity:
macOS: Unpatched Versions at Risk of App Sandbox Escape
CVE-2026-28891
macOS versions older than 15.7.5, 14.8.5, and 26.4 are exposed to a risk where an app could potentially break out of its security restrictions. If exploited, this could allow unauthorized access to se...
Xcode 26.4: Malicious app may cause sudden app crash
CVE-2026-28890
A security issue in Xcode 26.4 could allow a malicious app to crash your system. This has been fixed in the latest version of Xcode, which you should update to. Update Xcode to the latest version to p...
Xcode 26.3: Unrestricted File Access Through Elevated Privileges
CVE-2026-28889
An older version of Xcode has a bug that allows an app to read any file on a Mac with administrator privileges. This issue is fixed in Xcode 26.4. If you're using Xcode 26.3, update to Xcode 26.4 to f...
macOS: Root Privileges Can Be Gained Through Malicious App
CVE-2026-28888
A security issue has been fixed in some versions of macOS. This issue allowed an app to potentially gain root access, which could lead to unauthorized changes to your system. Update to the latest vers...
iOS, iPadOS, and other Apple operating systems may crash under certain conditions
CVE-2026-28886
A security fix has been released for Apple operating systems, which improves input validation to prevent a potential denial-of-service attack. This means that a malicious user with access to a network...
iOS App Can Potentially List All Installed Apps
CVE-2026-28882
A bug in Apple's operating system could have allowed an app to list all the apps installed on a user's device. This means a malicious app could have accessed sensitive information. Apple has released ...
macOS Update Fixes Data Access Risk
CVE-2026-28881
A patch in macOS Tahoe 26.4 prevents an app from accessing sensitive user data that was previously stored in an insecure location. This means user data is now better protected. Update to macOS Tahoe 2...
Apple Devices: Malicious Apps Can Access Installed Apps List
CVE-2026-28880
A security fix has been made to prevent malicious apps from accessing a list of installed apps on Apple devices. This is a concern because it could potentially allow a malicious app to gather sensitiv...
iOS, iPadOS, macOS, tvOS, visionOS, watchOS: Malicious Web Content Can Crash Device
CVE-2026-28879
Some Apple devices are vulnerable to a crash when processing malicious web content. This could happen if a user visits a compromised website or opens a malicious email attachment. To stay protected, m...
Apple Devices May Expose Installed Apps
CVE-2026-28878
Some Apple devices may inadvertently reveal a list of installed apps to certain apps. This can compromise user privacy. Apple has released updates to fix this issue, and you should update your devices...
Apple Devices: Unauthorized Access to Sensitive User Data
CVE-2026-28877
An issue allowed an app to potentially access sensitive user data without permission. This has been fixed in recent updates for various Apple devices. To stay secure, ensure all your Apple devices are...
Apple Devices: Sensitive Data Exposed by Improper Path Handling
CVE-2026-28876
A security issue in Apple's operating systems allowed an app to potentially access sensitive user data. This issue has been fixed in various versions of iOS, iPadOS, macOS, and visionOS. Update to the...
Apple iOS and iPadOS: Denial-of-Service Risk Fixed
CVE-2026-28875
A security update has fixed a weakness in Apple's iOS and iPadOS that could allow an attacker to disrupt service. This issue has been addressed in version 26.4. Update to the latest version to protect...
iOS and iPadOS: Unapproved App Termination via Malicious Input
CVE-2026-28874
A bug in iOS and iPadOS versions prior to 26.4 could allow a remote attacker to force an app to close unexpectedly. This could potentially disrupt your business operations if you rely on a specific ap...
Safari and iOS Websites May Crash or Be Hijacked
CVE-2026-28871
Some websites can cause Safari and iOS devices to crash or be taken over by malicious code. Apple has fixed this issue in updated versions of Safari, iOS, and iPadOS. Make sure your devices are up to ...
Apple Devices: Sensitive User Data Accessible to Malicious Apps
CVE-2026-28870
Apple has fixed a security issue in various operating systems that could allow a malicious app to access sensitive user data. This issue was fixed in recent updates to iOS, iPadOS, macOS, tvOS, vision...
iOS, iPadOS, macOS, visionOS, watchOS: Data Leaked by Malicious Apps
CVE-2026-28868
Some apps on Apple devices may be able to secretly leak sensitive information. This is a security risk because it could allow an attacker to gain access to confidential data. Apple has released update...
Apple Devices: Unauthorized Access to Kernel State
CVE-2026-28867
Some Apple devices can be vulnerable to a security risk if an attacker exploits a weakness in the way authentication works. This could potentially allow an app to gain access to sensitive information....
iDevices: Sensitive user data accessed through malicious symlinks
CVE-2026-28866
Some iOS, iPadOS, and macOS devices may be at risk of data breaches if an attacker tricks the system into accessing sensitive information through a symbolic link. Affected users should update to the l...
Apple Devices: Authentication Traffic Can Be Intercepted by Network Attackers
CVE-2026-28865
A security issue in Apple devices could allow an attacker on the same network to intercept sensitive information, such as login credentials. This issue has been fixed in several versions of Apple's op...
Apple Devices: Local attacker can access user's Keychain items
CVE-2026-28864
Some Apple devices are at risk of an attacker gaining access to sensitive user data, such as passwords and credit card numbers, if they have the device in their possession. This is a serious security ...
iOS, iPadOS, tvOS, watchOS: App May Fingerprint User
CVE-2026-28863
A security update has fixed a potential issue where an app could collect information about your device and use it to identify you. This was a risk, but the issue has been resolved in the latest softwa...
macOS: App may access sensitive user data in log entries
CVE-2026-28862
A security update for macOS improves how sensitive user data is hidden in log entries. This change will prevent apps from accessing private information by mistake. Update to the latest version of your...
Safari: Malicious websites may access sensitive browser data
CVE-2026-28861
A logic issue in Safari and other Apple operating systems allowed malicious websites to access sensitive browser data that was intended for other websites. This has been fixed in the latest updates, s...
Safari and Apple Devices: Malicious Websites Can Bypass Security
CVE-2026-28859
A security flaw in Safari and other Apple devices could allow a malicious website to access restricted content, potentially compromising the security of the device. This issue has been fixed in the la...