CVE Tools

Apple Updates Everything - SANS Internet Storm Center

SANS Internet Storm CenterBy SANS Internet Storm Center24 min read

PatchiOSmacOS

Our summary

Apple has rolled out a comprehensive suite of security updates for its entire ecosystem, including iOS, macOS, iPadOS, watchOS, visionOS, and tvOS. The release addresses a massive list of Common Vulnerabilities and Exposures (CVEs), ranging from kernel memory corruption and privilege escalation flaws to significant bugs in WebKit, ImageIO, and the Kernel.

Notable fixes include CVE-2026-43689 and CVE-2026-43786, which allow apps to gain root privileges, and multiple issues such as CVE-2026-43686 that enable kernel memory corruption via malicious NFS servers. Users are strongly advised to install these updates immediately to protect against potential exploits involving sensitive data leakage, remote code execution, and system instability.

Read at SANS Internet Storm Center

Below is the opening; the full story is at SANS Internet Storm Center.

From SANS Internet Storm Center

CVE-2022-3437: A user in a privileged network position may be able to leak sensitive user information.
Affects Heimdal     x x x       CVE-2026-20683: An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.
Affects Apple Account x   x x x…

Continue at SANS Internet Storm Center

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store