Full Disclosure mailing list archives
APPLE-SA-07-27-2026-3 macOS Sequoia 15.7.8
From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 27 Jul 2026 17:20:41 -0700
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-07-27-2026-3 macOS Sequoia 15.7.8 macOS Sequoia 15.7.8 addresses the following issues. Information about the security content is also available at https://support.apple.com/en-us/128071. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Accounts Available for: macOS Sequoia Impact: An app may be able to gain root privileges Description: A parsing issue in the handling of directory paths was addressed with improved path validation. CVE-2026-43749: Adam Franke, Trung Nguyen (@everping) of CyStack, Ashish Kunwar afpfs Available for: macOS Sequoia Impact: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-64767: Dave G. apache Available for: macOS Sequoia Impact: A remote attacker may be able to cause a denial-of-service Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org. CVE-2026-23918: Юлия Мерцалова APFS Available for: macOS Sequoia Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-64695: Peter Malone App Store Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved checks. CVE-2026-43801: Rahul Raj Apple Account Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: A race condition was addressed with improved state handling. CVE-2026-43781: Pinak Oza Apple Account Available for: macOS Sequoia Impact: A malicious app may be able to break out of its sandbox Description: An authorization issue was addressed with improved state management. CVE-2026-64737: Robert Mindo Apple Neural Engine Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-43748: an anonymous researcher, tamdao, Franco Belman at Blackwing Intelligence AppleDouble Available for: macOS Sequoia Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-43776: Peter Malone, Nicolas Rabrenovic, Irvin Wang AppleRAID Available for: macOS Sequoia Impact: A local user may be able to read kernel memory Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-43681: impost0r (ret2plt), David Ige - Beryllium Security Assets Available for: macOS Sequoia Impact: A malicious application may be able to bypass Privacy preferences Description: An authorization issue was addressed with improved state management. CVE-2026-43672: 이재영 ATS Available for: macOS Sequoia Impact: An app may be able to read files outside of its sandbox Description: A permissions issue was addressed by removing the vulnerable code. CVE-2026-43763: Pavan Nallamothu, Jared Reyes Audio Available for: macOS Sequoia Impact: An app may be able to break out of its sandbox Description: An access issue was addressed with additional sandbox restrictions. CVE-2026-64702: John Lussier Audio Available for: macOS Sequoia Impact: An app may be able to cause a denial-of-service Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-64725: Seonung Park, ALTV!ST (altvi.st/) AVEVideoEncoder Available for: macOS Sequoia Impact: An app may be able to execute arbitrary code with kernel privileges Description: A buffer overflow was addressed with improved size validation. CVE-2026-64747: Franco Belman at Blackwing Intelligence AVEVideoEncoder Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-64762: Franco Belman at Blackwing Intelligence, Dun BackgroundAssets Available for: macOS Sequoia Impact: An app may be able to delete files for which it does not have permission Description: A permissions issue was addressed with improved validation. CVE-2026-64707: YingQi Shi (@Mas0nShi) of DBAppSecurity's WeBin lab BOM Available for: macOS Sequoia Impact: A maliciously crafted ZIP archive may bypass Gatekeeper checks Description: The issue was addressed with improved checks. CVE-2026-28849: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs cd9660 Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination or read kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-64698: Richard Zana, Peter Malone, Nathaniel Oh (@calysteon), an anonymous researcher Contacts Available for: macOS Sequoia Impact: Processing a maliciously crafted contact may leak sensitive data Description: The issue was addressed with improved checks. CVE-2026-64734: Daniel Williams Control Center Available for: macOS Sequoia Impact: An app may be able to access user-sensitive data Description: A logic issue was addressed with improved validation. CVE-2026-43756: 이재영 Core Services Available for: macOS Sequoia Impact: An app may be able to gain root privileges Description: A race condition was addressed with improved state handling. CVE-2026-43693: Gergely Kalman (@gergely_kalman) CoreAudio Available for: macOS Sequoia Impact: Processing a maliciously crafted audio file may corrupt process memory Description: The issue was addressed with improved memory handling. CVE-2026-43673: Anonymous working with TrendAI Zero Day Initiative CoreAudio Available for: macOS Sequoia Impact: Processing an audio stream in a maliciously crafted media file may terminate the process Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-43744: Mathis Mansière, an anonymous researcher CoreAudio Available for: macOS Sequoia Impact: A remote attacker may be able to cause unexpected system termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-43803: Rahul Raj CoreMedia Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-43775: Csaba Fitzl (@theevilbit) of Iru CoreMedia Available for: macOS Sequoia Impact: Processing a maliciously crafted video file may lead to unexpected app termination Description: A memory corruption issue was addressed with improved memory handling. CVE-2026-43711: James Duffy (@0x4A616D657344) CoreServices Available for: macOS Sequoia Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: The issue was addressed with improved checks. CVE-2026-28936: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs CoreUI Available for: macOS Sequoia Impact: Processing a maliciously crafted asset catalog may result in disclosure of process memory Description: The issue was addressed with improved memory handling. CVE-2026-43738: Peter Malone CoreVideo Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-43802: an anonymous researcher Crash Reporter Available for: macOS Sequoia Impact: An app may be able to leak sensitive user information Description: A privacy issue was addressed by removing sensitive data. CVE-2026-64710: Matthew Schneider CUPS Available for: macOS Sequoia Impact: A malicious app may be able to gain root privileges Description: A permissions issue was addressed with additional restrictions. CVE-2026-39875: XBreach.ai, Dallas Dubs, Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs, Aaron Grattafiori - NVIDIA AI Red Team CUPS Available for: macOS Sequoia Impact: An app may be able to gain root privileges Description: An injection issue was addressed with improved validation. CVE-2026-43698: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs curl Available for: macOS Sequoia Impact: Authentication credentials may be sent to a server on another origin Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org. CVE-2026-3784 CVE-2026-3783 Data Detectors UI Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-43758: HvxyZLF DesktopServices Available for: macOS Sequoia Impact: An app may bypass Gatekeeper checks Description: A file quarantine bypass was addressed with additional checks. CVE-2026-64708: Lance Cain - Offensive Security Engineer, SpecterOps Inc. Disk Images Available for: macOS Sequoia Impact: An app may be able to elevate privileges Description: A race condition was addressed with improved state handling. CVE-2026-28926: Jonathan Bar Or (@yo_yo_yo_jbo) Disk Images Available for: macOS Sequoia Impact: Parsing a maliciously crafted file may lead to an unexpected app termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-43747: Anthony Laou Hine Tsuei (@anarcheuz) Disk Images Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: An integer overflow was addressed with improved input validation. CVE-2026-64694: Gil Portnoy & Henry Disk Images Available for: macOS Sequoia Impact: An app may be able to bypass network restrictions Description: A permissions issue was addressed with additional sandbox restrictions. CVE-2026-28945: Ayaan Ahmad Disk Images Available for: macOS Sequoia Impact: An app may be able to disclose kernel memory Description: The issue was addressed with improved bounds checks. CVE-2026-64776: Hyunwoo Kim (@v4bel) DriverKit Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation. CVE-2026-43793: erdene-och Byambabayar DriverKit Available for: macOS Sequoia Impact: An attacker with physical access to a locked device may be able to view sensitive user information Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-43753: Niels Hofmans Foundation Available for: macOS Sequoia Impact: A malicious app may be able to access protected user data Description: The issue was addressed with improved input sanitization. CVE-2026-43714: an anonymous researcher Game Center Available for: macOS Sequoia Impact: A malicious app may be able to break out of its sandbox Description: A parsing issue in the handling of directory paths was addressed with improved path validation. CVE-2026-64740: Manuel Fernandez (Stackhopper Security) Game Center Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved data protection. CVE-2026-43796: Stanislav Jelezoglo, Ilya Andr (andrd3v) of Positive Technologies Heimdal Available for: macOS Sequoia Impact: An app may be able to cause a denial-of-service Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-64692: Redon Gashi HFS Available for: macOS Sequoia Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-43682: Trung Nguyen (@everping) of CyStack, Peter Malone, Nicolas Rabrenovic, Dave G., Atul R V & Ashmit Sharma HFS Available for: macOS Sequoia Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-28981: Hcamael and 章鱼哥@aipy (aipyaipy.com), Aswin Kumar Gokulakannan, Surya Narayan Kushwaha, Dun HFS Available for: macOS Sequoia Impact: Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-43773: Surya Narayan Kushwaha, Richard Zana, Peter Malone, Hyunwoo Kim (@v4bel), Cem Onat Karagun HFS Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: The issue was addressed with improved memory handling. CVE-2026-43767: Hyunwoo Kim (@v4bel) HFS Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-64697: Peter Malone HFS Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: An integer overflow was addressed with improved input validation. CVE-2026-43764: Tristan Madani (@TristanInSec) from Talence Security HFS Available for: macOS Sequoia Impact: An attacker may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-43710: Peter Malone Icons Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: An access issue was addressed with additional sandbox restrictions. CVE-2025-43325: an anonymous researcher ImageIO Available for: macOS Sequoia Impact: Processing a maliciously crafted image may corrupt process memory Description: The issue was addressed with improved memory handling. CVE-2026-64716: Peter Malone, Jonathan Alush-Aben, Arni Hardarson ImageIO Available for: macOS Sequoia Impact: Processing a maliciously crafted texture may lead to unexpected app termination Description: An integer overflow was addressed with improved input validation. CVE-2026-43780: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative ImageIO Available for: macOS Sequoia Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: An integer overflow was addressed with improved input validation. CVE-2026-43818: an anonymous researcher ImageIO Available for: macOS Sequoia Impact: Processing a maliciously crafted image may corrupt process memory Description: A buffer overflow issue was addressed with improved memory handling. CVE-2026-43661: Gandalf4a of PKU-ICODE, Anton Pakhunov, an anonymous researcher ImageIO Available for: macOS Sequoia Impact: Processing a maliciously crafted file may lead to a denial-of-service Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-64754: Rahul Raj, PETOWORKS의 Bugeun Choi (@Bugeun) ImageIO Available for: macOS Sequoia Impact: Processing a maliciously crafted image may lead to a denial-of-service Description: A type confusion issue was addressed with improved checks. CVE-2026-64693: Geonha Lee (@leegn4a) IOKit Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination or write kernel memory Description: A race condition was addressed with improved state handling. CVE-2026-43805: 이재영 IOSkywalkFamily Available for: macOS Sequoia Impact: An app may be able to disclose kernel memory Description: A memory corruption issue was addressed with improved memory handling. CVE-2026-39877: Richard Zana, Dhiyanesh Selvaraj (@redroot97) Kernel Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-64749: hxr1, Hiroki Imai (LAC Co., Ltd.), Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ashish Kunwar Kernel Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved checks. CVE-2026-43782: Igor Ushakov Kernel Available for: macOS Sequoia Impact: An app may be able to disclose kernel memory Description: An information leakage was addressed with additional validation. CVE-2026-64744: Ryan Hileman via Xint Code (xint.io) Kernel Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-64775: Ryan Hileman via Xint Code (xint.io) Kernel Available for: macOS Sequoia Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory Description: A race condition was addressed with improved locking. CVE-2026-28982: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Adam Doupé of ASU SEFCOM Kernel Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A use after free issue was addressed with improved memory management. CVE-2026-43778: f0r of MurphySec, Mahmoud Abdelmoniem, Feng Xue and XGPT of ThreatBook, Wang Yu, Nicolas Rabrenovic, Lyutoon, Hiroki Imai (LAC Co., Ltd.), Fábio Luís @scanpt, DARKNAVY (@DarkNavyOrg), an anonymous researcher Kernel Available for: macOS Sequoia Impact: A remote attacker may be able to bypass network filters Description: An inconsistent user interface issue was addressed with improved state management. CVE-2026-64735: Gor Aleksanyan Kernel Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-43822: Michal Kosiorek, Eddy Tsalolikhin CVE-2026-64700: Asjid Kalam (@odinshell) CVE-2026-43799: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Sequoia Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-43810: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination or write kernel memory Description: The issue was addressed with improved input sanitization. CVE-2026-43724: impost0r (ret2plt), Hyunwoo Kim (@v4bel) Kernel Available for: macOS Sequoia Impact: An app may be able to leak sensitive kernel state Description: The issue was addressed with improved input sanitization. CVE-2026-43722: Hyunwoo Kim (@v4bel), Feng Xue and XGPT of ThreatBook Kernel Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-43809: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-43757: Wang Yu, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: An integer overflow was addressed with improved input validation. CVE-2026-43769: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Sequoia Impact: An app may be able to leak sensitive kernel state Description: This issue was addressed with improved redaction of sensitive information. CVE-2026-43754: Ernesto Martínez García, Calif Research Kernel Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: A logic issue was addressed with improved checks. CVE-2026-64723: Ji'an Zhou, Mingxuan Yang, Ye Zhang Kernel Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: This issue was addressed with improved input validation. CVE-2026-39868: Ye Zhang (@VAR10CK) of Baidu Security, Vladislav Shevchenko (Positive Technologies), Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Sequoia Impact: An app may be able to disclose kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-64709: Pasquale Scola, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: This issue was addressed through improved state management. CVE-2026-64721: Lukas Gerlach LaunchServices Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: An information disclosure issue was addressed with improved privacy controls. CVE-2026-20672: Kirin (@Pwnrin) and LFY (@secsys) from Fudan University LaunchServices Available for: macOS Sequoia Impact: A remote attacker may be able to cause a denial of service Description: A type confusion issue was addressed with improved checks. CVE-2026-28983: Ruslan Dautov libarchive Available for: macOS Sequoia Impact: Processing a maliciously crafted file may result in disclosure of process memory Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org. CVE-2026-4424 libarchive Available for: macOS Sequoia Impact: A maliciously crafted ZIP archive may bypass Gatekeeper checks Description: A file quarantine bypass was addressed with additional checks. CVE-2026-28900: Prathamesh Walunj libc Available for: macOS Sequoia Impact: A malicious app may be able to break out of its sandbox Description: An integer overflow was addressed with improved input validation. CVE-2026-28973: an anonymous researcher Libnotify Available for: macOS Sequoia Impact: An attacker may be able to cause unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-64739: Feng Xue and XGPT of ThreatBook, Dun libxslt Available for: macOS Sequoia Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: The issue was addressed with improved memory handling. CVE-2026-43703: Tristan Madani (@TristanInSec) from Talence Security libxslt Available for: macOS Sequoia Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: A double free issue was addressed with improved memory management. CVE-2026-43706: Tristan Madani (@TristanInSec) from Talence Security LoginWindow Available for: macOS Sequoia Impact: An attacker with physical access to a locked device may be able to view sensitive user information Description: An authorization issue was addressed with improved state management. CVE-2026-43766: Amy (amys.website) Maps Available for: macOS Sequoia Impact: A malicious app may be able to break out of its sandbox Description: A permissions issue was addressed with additional restrictions. CVE-2026-64738: Robert Mindo, Nathaniel Oh (@calysteon) mDNSResponder Available for: macOS Sequoia Impact: An attacker on the local network may be able to cause a denial-of-service Description: The issue was addressed with improved memory handling. CVE-2026-43653: Atul R V CVE-2026-64724: Daisuke Hatakeyama (@SYZD Research) MediaRemote Available for: macOS Sequoia Impact: An app may be able to gain root privileges Description: A path handling issue was addressed with improved validation. CVE-2026-43723: Richard Zana, Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs MobileAccessoryUpdater Available for: macOS Sequoia Impact: A malicious accessory may be able to cause unexpected app termination Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-43807: Tristan Madani (@TristanInSec) from Talence Security Model I/O Available for: macOS Sequoia Impact: Processing a maliciously crafted image may corrupt process memory Description: The issue was addressed with improved memory handling. CVE-2026-43733: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative CVE-2026-43729: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative Model I/O Available for: macOS Sequoia Impact: A remote attacker may be able to cause unexpected application termination or heap corruption Description: An out-of-bounds write issue was addressed with improved input validation. CVE-2026-64772: wh0am1i, stratan (@5tratan) Model I/O Available for: macOS Sequoia Impact: A remote attacker may be able to cause unexpected application termination or heap corruption Description: An integer overflow was addressed with improved input validation. CVE-2026-64774: stratan (@5tratan) Model I/O Available for: macOS Sequoia Impact: A remote attacker may be able to cause unexpected application termination or heap corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-64770: stratan (@5tratan) CVE-2026-64769: stratan (@5tratan) Model I/O Available for: macOS Sequoia Impact: Processing a 3D model may result in disclosure of process memory Description: A buffer overflow issue was addressed with improved memory handling. CVE-2026-64722: wh0am1i Model I/O Available for: macOS Sequoia Impact: A remote attacker may cause an unexpected app termination Description: An out-of-bounds read issue was addressed with improved input validation. CVE-2026-64768: stratan (@5tratan) Model I/O Available for: macOS Sequoia Impact: A remote attacker may be able to cause unexpected application termination or heap corruption Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-64771: wh0am1i Net-SNMP Available for: macOS Sequoia Impact: An app may be able to cause a denial-of-service Description: A stack overflow was addressed with improved input validation. CVE-2026-43771: Robert Tran NetFSFramework Available for: macOS Sequoia Impact: An app may be able to break out of its sandbox Description: A path traversal issue was addressed with improved input validation. CVE-2026-43772: Mickey Jin (@patch1t) Network Extensions Available for: macOS Sequoia Impact: An attacker with physical access to a locked device may be able to view sensitive user information Description: This issue was addressed with improved checks. CVE-2026-28961: Dan Raviv NSColorPanel Available for: macOS Sequoia Impact: An app may be able to leak sensitive user information Description: This issue was addressed with additional entitlement checks. CVE-2026-64711: Koh M. Nakagawa (@tsunek0h) of FFRI Security, Inc. PackageKit Available for: macOS Sequoia Impact: A user may be able to elevate privileges Description: A logic issue was addressed with improved restrictions. CVE-2026-28912: Matej Moravec (@MacejkoMoravec) PackageKit Available for: macOS Sequoia Impact: An app may be able to modify protected parts of the file system Description: This issue was addressed with improved handling of symlinks. CVE-2026-43765: Mickey Jin (@patch1t) ppp Available for: macOS Sequoia Impact: An attacker may be able to cause unexpected system termination or read kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-28896: Dave G. Printing Available for: macOS Sequoia Impact: A malicious app may be able to break out of its sandbox Description: A path handling issue was addressed with improved validation. CVE-2026-64731: Sindre Sorhus, Richard Zana Pro Res Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-43812: Francisco Knabe quarantine Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination or write kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-43694: Hcamael and 章鱼哥@aipy (aipyaipy.com), JC Alvarado of Stripe, Jacob Hazak Remote Management Available for: macOS Sequoia Impact: A malicious app may be able to gain root privileges Description: A permissions issue was addressed with additional restrictions. CVE-2026-39874: @pixiepointsec SceneKit Available for: macOS Sequoia Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-64764: stratan (@5tratan) SceneKit Available for: macOS Sequoia Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution Description: An out-of-bounds write issue was addressed by removing the vulnerable code. CVE-2026-64763: stratan (@5tratan) SceneKit Available for: macOS Sequoia Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution Description: An integer overflow was addressed with improved input validation. CVE-2026-64766: stratan (@5tratan) CVE-2026-64765: stratan (@5tratan) Screen Sharing Server Available for: macOS Sequoia Impact: An app may be able to intercept network connections intended for another process Description: A logic issue was addressed with improved restrictions. CVE-2026-43779: Dave G., Asaf Cohen Screen Sharing Server Available for: macOS Sequoia Impact: A remote attacker may be able to cause a denial of service Description: This issue was addressed with improved input validation. CVE-2026-43777: Junming C.(Chapoly1305) Screen Sharing Server Available for: macOS Sequoia Impact: A local attacker may be able to determine the legacy VNC password configured for Screen Sharing Description: This issue was addressed with additional entitlement checks. CVE-2026-43665: Ayaan Ahmad Siri Available for: macOS Sequoia Impact: A person with physical access to a locked device may be able to access contacts and photos Description: This issue was addressed with additional restrictions on the lock screen. CVE-2026-64745: Vivek Dhar, ASI (RM) in Border Security Force, FTR HQ BSF Kashmir SMB Available for: macOS Sequoia Impact: Connecting to a malicious SMB server may lead to unexpected system termination Description: The issue was addressed with improved memory handling. CVE-2026-39873: Peter Malone SMB Available for: macOS Sequoia Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-64696: Feng Xue and XGPT of ThreatBook, Peter Malone SMB Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: A type confusion issue was addressed with improved memory handling. CVE-2026-64704: Claudio Bozzato and Francesco Benvenuto of Cisco Talos, Aswin Kumar Gokulakannan, Peter Malone, Calif.io in collaboration with Claude and Anthropic Research, Kitten Food Spotlight Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-43774: Csaba Fitzl (@theevilbit) of Iru StorageKit Available for: macOS Sequoia Impact: An app may be able to access sensitive user data Description: A race condition was addressed with additional validation. CVE-2026-43770: Tien-Chih Lin of CyCraft Technology udf Available for: macOS Sequoia Impact: An app may be able to cause unexpected system termination Description: The issue was addressed with improved memory handling. CVE-2026-43768: Hyunwoo Kim (@v4bel) WebDAV Available for: macOS Sequoia Impact: An app may be able to cause a denial-of-service Description: A use after free issue was addressed with improved memory management. CVE-2026-64703: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research WebDAV Available for: macOS Sequoia Impact: An app may be able to disclose kernel memory Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-64699: Bruce Dang of Calif.io Wi‑Fi Available for: macOS Sequoia Impact: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-43750: an anonymous researcher xar Available for: macOS Sequoia Impact: An app may be able to cause a denial of service Description: A logic issue existed resulting in memory corruption. This was addressed with improved state management. CVE-2026-28932: Mathis Mansière zip Available for: macOS Sequoia Impact: A maliciously crafted ZIP archive may bypass Gatekeeper checks Description: A logic issue was addressed with improved file handling. CVE-2026-28914: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs (nosebeard.co) Additional recognition Audio We would like to acknowledge Niels Hofmans for their assistance. copyfile We would like to acknowledge Keisuke Hosoda for their assistance. CoreMedia We would like to acknowledge yaohway for their assistance. Disk Images We would like to acknowledge Jordy Zomer (@pwningsystems), Phillip Groves, Richard Zana for their assistance. Kernel We would like to acknowledge Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Chris Betz, James Duffy ( @0x4A616D657344 ), Mathis Mansière, Tristan Rousseau, Yeojin Kim, YingMuo (@YingMuo) of DEVCORE Research Team for their assistance. libxslt We would like to acknowledge Kubilay Berk Alkan for their assistance. mDNSResponder We would like to acknowledge Cem Onat Karagun, He Wei (ギカク), Jex Amro, 章鱼哥 (@aipy) of aipyaipy.com for their assistance. PluginKit We would like to acknowledge Asaf Cohen, Ashish Kunwar for their assistance. Printing UIKit We would like to acknowledge Jacolon Walker ( @call_eax ) for their assistance. ReplayKit We would like to acknowledge an anonymous researcher for their assistance. Spotlight We would like to acknowledge Ilya Andr (andrd3v) and nkhmelni for their assistance. System Settings We would like to acknowledge Masaki Moriguchi for their assistance. Time Machine We would like to acknowledge Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs for their assistance. macOS Sequoia 15.7.8 may be obtained from the Mac App Store or Apple's Software Downloads web site: https://support.apple.com/downloads/ All information is also posted on the Apple Security Releases web site: https://support.apple.com/100100. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmpn4X8ACgkQ4Ifiq8DH 7PXhdw//SwxR1HBrajWl+GeT9HyV9LX0cuStiQll8ZVS5c59T4oO59FJNNAGX/dr SeCNcJwlj62DnXNbdXUq6MHvhSXgPyFhFBYwOgKBnwdH3nu0R5h0B36nXpmUirw8 OV2Em4D1KK/LAtybln4iRqJtIHDe0epfcFaoVtSQfDBEeYOkftqoQDzvIuygckFs wSzM/qoOPkrJ2wWORUjf+JFB3VpF9TwXfPR/lhZ3ae20l3tv/iL/d3JR4+N5quNj 7iz1UEpMzb32UFMD51B4pJivBkuRkyG9oYpBXjD7PcLUy02SErfWtEHpUlsxRTEe 3j23q/cbZTD15ey7hka1aTWh+1y99rEA/X9tQfYLylHLtGO2RihwofezxZrhzl7z 3L9BV+R+p9h9hM+DQg9pwimuI+YiNdQhIyo7dek63a1bGXC6n5yoXM6hZYCgAfnZ ODwOI1sRhsZklbY5qArLjh3qBPmW8BzSkeewOJ/Q7ji2+Lyc8m2OTEJSHYgi9uxL GFrLnhaBHdkXONK6IoKEAuH4ziKUK7TJa0N1Ye5FMfWokGGhfuUeZdJgeXARs8S6 DWolFcbD6iReEgx57t6iqFZUWO7ONSNLUaap9gJHEl1jxhLPj5fhHe1x/Iz2RPFW htTbAyzepDqQful4i9ngelfeMdmHY9jIURuveWC8L/G1z2mSg1E= =E61h -----END PGP SIGNATURE----- _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- APPLE-SA-07-27-2026-3 macOS Sequoia 15.7.8 Apple Product Security via Fulldisclosure (Aug 06)
