macOS Security News

Security news specific to Apple macOS — vulnerabilities, malware and patches affecting Mac systems.

macOS has a smaller attack surface than Windows in raw volume but is an increasingly common target as adoption grows in enterprise environments. This feed tracks macOS-specific vulnerabilities, malware families targeting Macs, and Apple's security update releases as they are reported. It is useful for tracking a platform that gets proportionally less mainstream security coverage than it now deserves.

Recent macOS items

2026-09-01: Essential macOS Stealer infection https://www.malware-traffic-analysis.net/2026/09/01/index.html 🎖
@malwr · Sep 5, 2026
CVE-2026-82635 Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traver…
@cveNotify · Sep 4, 2026
Contagious Interview: Trojanized macOS Installers Jamf Threat Labs uncovers 14 trojanized macOS DMGs and PKGs tied to the DPRK-attributed Contagious Interview campaign. Learn more. https://www.jamf.co…
@malwr · Sep 4, 2026
CVE-2026-20281 A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could…
@cveNotify · Sep 2, 2026
CVE-2026-20281 A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could…
@cveNotify · Sep 2, 2026
CVE-2026-20281 A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could…
@cveNotify · Sep 2, 2026
Hunting macOS Amnesia Stealer in Elastic Following Amnesia Stealer through macOS endpoint telemetry in Elastic. https://jasonphang98.github.io/posts/amnesia-stealer/ 🎖
@malwr · Sep 2, 2026
CVE-2026-19592 OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmoni…
@cveNotify · Sep 1, 2026
CVE-2026-19591 OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted…
@cveNotify · Sep 1, 2026
CVE-2026-19590 OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user…
@cveNotify · Sep 1, 2026
Iranian hackers are posing as recruiters on LinkedIn and hiding cross-platform remote access trojans inside coding tests.The campaign, attributed to Nimbus Manticore, delivers two newly documented mal…
@thehackernews · Sep 1, 2026
CVE-2026-82635 Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traver…
@cveNotify · Aug 31, 2026
CVE-2026-59111 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables…
@cveNotify · Aug 31, 2026
CVE-2026-82635 Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traver…
@cveNotify · Aug 30, 2026
gcarmix/HexWalk: Hex Viewer/Editor/Analyzer compatible with Linux/Windows/MacOS https://github.com/gcarmix/hexwalk 🎖
@malwr · Aug 28, 2026
CVE-2026-12556 Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege.…
@cveNotify · Aug 27, 2026
CVE-2026-12555 Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege.…
@cveNotify · Aug 27, 2026
CVE-2026-12554 Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege.…
@cveNotify · Aug 27, 2026
CVE-2026-65182 Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrict…
@cveNotify · Aug 27, 2026
CVE-2026-68525 Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not…
@cveNotify · Aug 27, 2026
CVE-2026-65927 Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule.This issu…
@cveNotify · Aug 27, 2026
CVE-2026-65905 Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated reque…
@cveNotify · Aug 27, 2026
CVE-2026-68569 Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in t…
@cveNotify · Aug 27, 2026
CVE-2026-73180 Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been establish…
@cveNotify · Aug 27, 2026
CVE-2026-73180 Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been establish…
@cveNotify · Aug 25, 2026
CVE-2026-68569 Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in t…
@cveNotify · Aug 25, 2026
CVE-2026-68525 Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not…
@cveNotify · Aug 25, 2026
CVE-2026-65905 Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated reque…
@cveNotify · Aug 25, 2026
CVE-2026-65182 Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrict…
@cveNotify · Aug 25, 2026
CVE-2026-64705 A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7. An app may be able to cause unexpected system terminatio…
@cveNotify · Aug 25, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.