macOS Security News

Security news specific to Apple macOS: vulnerabilities, malware and patches affecting Mac systems.

macOS has a smaller attack surface than Windows in raw volume, but it is an increasingly common target as enterprise adoption grows. macOS-specific vulnerabilities, malware families targeting Macs, and Apple's security update releases show up here.

Recent macOS items

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks 🖋️ Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may ha…
@cibsecurity · Sep 28, 2026
CVE-2026-86950 An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a mal…
@cveNotify · Sep 28, 2026
Apple patched a new CoreGraphics flaw that may have been exploited in targeted iOS attacks. CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are…
@thehackernews · Sep 28, 2026
CVE-2026-63449 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/ parser.rs s…
@cveNotify · Sep 28, 2026
rPlayHub - Xcode DeviceHub reverse engineered - an open source project on GitHub https://github.com/rPlayAI/rPlayHub
@secharvester · Sep 28, 2026
CVE-2026-101045 Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this meta…
@cveNotify · Sep 27, 2026
CVE-2026-84549 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS serve…
@cveNotify · Sep 27, 2026
CVE-2024-46060 Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable file…
@cveNotify · Sep 26, 2026
ngwg/ceasta: disassembler, decompiler and debugger in one, with a built-in mcp server: point an ai at a binary and it can debug it, not just read it. ida-style listing, pseudocode (f5), x64dbg-style d…
@malwr · Sep 26, 2026
CVE-2026-100581 OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device bac…
@cveNotify · Sep 26, 2026
CVE-2025-7007 NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to crash.This issue af…
@cveNotify · Sep 26, 2026
CVE-2025-10101 Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may allow Local Execution of Code or Denial-of-Service of the antivirus process. Th…
@cveNotify · Sep 26, 2026
CVE-2025-43507 A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An…
@cveNotify · Sep 26, 2026
CVE-2025-43503 An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Taho…
@cveNotify · Sep 26, 2026
CVE-2025-43499 This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may…
@cveNotify · Sep 26, 2026
CVE-2025-43493 The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Visiting a mal…
@cveNotify · Sep 26, 2026
CVE-2025-43458 This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visi…
@cveNotify · Sep 26, 2026
CVE-2025-43444 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1…
@cveNotify · Sep 26, 2026
CVE-2025-43443 This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, wa…
@cveNotify · Sep 26, 2026
CVE-2025-43448 This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,…
@cveNotify · Sep 26, 2026
CVE-2025-43445 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.…
@cveNotify · Sep 26, 2026
CVE-2025-43438 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visio…
@cveNotify · Sep 26, 2026
CVE-2025-43434 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visio…
@cveNotify · Sep 26, 2026
CVE-2025-43429 A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, v…
@cveNotify · Sep 26, 2026
CVE-2025-43426 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data. 🎖
@cveNotify · Sep 26, 2026
CVE-2025-43423 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, vision…
@cveNotify · Sep 26, 2026
CVE-2025-43399 This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be abl…
@cveNotify · Sep 26, 2026
CVE-2025-43389 A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,…
@cveNotify · Sep 26, 2026
CVE-2025-43386 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, vi…
@cveNotify · Sep 26, 2026
CVE-2025-43385 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tah…
@cveNotify · Sep 26, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.