Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 25 March 2026
RSS112 vulnerabilities published on 25 March 2026
Severity:
macOS: Unapproved apps may gain elevated privileges
CVE-2026-28821
A bug in macOS's entitlement verification system allowed some apps to gain access to more privileges than they should have. This could lead to security issues if an attacker exploited it. The issue is...
macOS Tahoe 26.4: Sensitive user data access
CVE-2026-28820
An issue in macOS Tahoe 26.4 could allow an app to access sensitive user data. This could be a concern for users who store confidential information on their Macs. To fix this issue, update to macOS Ta...
macOS Logging Issue Allows Sensitive User Data Exposure
CVE-2026-28818
A flaw in the macOS logging system could allow an app to access sensitive user data. This issue has been fixed in recent updates to macOS, so you should update your operating system to the latest vers...
macOS: A sandbox might be bypassed by a malicious process
CVE-2026-28817
A security issue was fixed in newer versions of macOS. If left unpatched, a malicious program running in a restricted environment might be able to do more than it's supposed to. Update to macOS Sequoi...
macOS: Some apps may delete files they shouldn't
CVE-2026-28816
An issue in macOS allowed certain apps to delete files they didn't have permission to delete. This has been fixed in the latest updates for macOS Sequoia, Sonoma, and Tahoe. Users should update their ...
macOS: Malicious app can connect to network share without permission
CVE-2026-20701
An outdated version of macOS may allow an app to connect to a network share without the user's consent, potentially exposing sensitive data. This issue has been fixed in newer versions of macOS, so up...
Intel-based Macs: Apps Can Access Sensitive Data Due to Code-Signing Error
CVE-2026-20699
Intel-based Mac users need to update their operating system to macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, or macOS Tahoe 26.3/26.4 to prevent potential security risks. If not updated, an app may be ab...
iOS App Can Crash Device or Corrupt System Memory
CVE-2026-20698
An app could potentially cause your iOS device to crash or corrupt its system memory, leading to data loss or other issues. This issue has been fixed in the latest versions of iOS, iPadOS, macOS, tvOS...
macOS: Unrestricted App Access to User Data
CVE-2026-20697
A vulnerability in macOS allowed an app to access sensitive user data without permission. This has been fixed in recent updates, so make sure your system is up to date to prevent unauthorized access. ...
macOS: A security issue allows an app to see kernel memory layout
CVE-2026-20695
A security issue was fixed in macOS versions 15.7.5, 14.8.5, and 26.4. This issue could have allowed a malicious app to learn the layout of the kernel's memory, potentially allowing it to exploit othe...
Symlink Handling Issue in Apple Operating Systems
CVE-2026-20694
An update has fixed a security issue in Apple's operating systems that allowed an app to access user-sensitive data. This affects iOS, iPadOS, and several versions of macOS. Users should ensure their ...
macOS: Malicious users with root access can delete system files
CVE-2026-20693
A security issue in macOS allowed users with administrative access to delete files that were protected from deletion. This has been fixed in newer versions of macOS. If you're using an outdated versio...
Apple Mail Doesn't Always Hide IP Address or Block Remote Content
CVE-2026-20692
Some users may see their IP address exposed in emails, or receive unwanted remote content. This is fixed in the latest iOS, iPadOS, and macOS updates. Update your devices to the latest versions to pro...
Safari and Apple devices may leak user info to malicious websites
CVE-2026-20691
A security update in Safari and Apple devices fixes a bug that could allow malicious websites to learn more about you, such as your device and browser settings. This could be used to target you with t...
Apple Products: Malicious Audio Files Can Crash Your Device
CVE-2026-20690
If you use Apple devices, update to the latest version of your operating system to prevent a malicious audio file from crashing your device. This issue has been fixed in various versions of iOS, iPadO...
iOS and macOS apps may escape their boundaries
CVE-2026-20688
A software update has fixed a security issue that could allow a malicious app to break out of its normal restrictions and access sensitive areas of the operating system. This issue has been addressed ...
Apple Devices: Malicious App Can Crash System or Write to Memory
CVE-2026-20687
A issue was found in Apple's operating systems that could allow a malicious app to crash the device or write unauthorized data to memory. This is a security risk because it could lead to loss of data ...
App may access sensitive user data on iOS and iPadOS devices
CVE-2026-20686
A security issue has been fixed in iOS 26.3 and iPadOS 26.3, which could have allowed an app to access sensitive user information. This means that users with these software updates are now protected f...
MacOS Tahoe 26.4: Unrestricted App Installation Risk
CVE-2026-20684
A fix was made in macOS version 26.4 to prevent an app from bypassing security checks. This means an app might be able to be installed on a Mac even if it shouldn't be. If you're using macOS 26.4, upd...
macOS Sonoma and macOS Tahoe: Unauthorized App Access to User Data
CVE-2026-20670
A software update has fixed a bug in macOS Sonoma and macOS Tahoe that could allow an unauthorized app to access sensitive user data. This update is available now, and it's recommended that you instal...
Sensitive user data may be accessed by an app
CVE-2026-20668
A security issue was fixed in various Apple operating systems, which could have allowed an app to access sensitive user data. This risk has been addressed in recent software updates. Apple recommends ...
Safari: Malicious websites can disable security settings
CVE-2026-20665
Malicious websites could potentially bypass Safari's security features, allowing them to act in unintended ways. This issue has been fixed in the latest versions of Safari and other Apple operating sy...
Safari and Apple Devices Crash Risk from Malicious Web Content
CVE-2026-20664
Processing malicious web content on Safari or certain Apple devices may cause the system to crash. This issue is fixed in the latest versions of Safari, iOS, iPadOS, macOS, and visionOS. Update to the...
Parsing a malicious file can crash an iPhone, iPad, or Mac app
CVE-2026-20657
A vulnerability in iOS and macOS devices could cause an app to crash if it's given a specially designed file. This could happen if a user opens a file from an unknown source. Apple has fixed this issu...
Sensitive user data may be accessed by an app
CVE-2026-20651
A security update for macOS has fixed a potential issue where a malicious app could access sensitive user information. This update is available in macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, and macOS ...