4.4
CVE-2026-20603 - Improper Redaction Allows Root-Privileged Apps to Access Private Information in macOS
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26.3. An app with root privileges may be able to access private information.
5.5
CVE-2026-20602 - Cache Handling Vulnerability Leading to Denial of Service in macOS
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to cause a denial-of-service.
5.5
CVE-2026-20655 -
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
7.8
CVE-2026-20614 - Root Privilege Escalation via Path Handling in macOS
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to gain root privileges.
5.5
CVE-2026-20680 - Sandboxed App Observability Bypass Leading to Sensitive Data Exposure
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. A sandboxed app may be able to access sensitive user data.
5.5
CVE-2026-20638 - Live Caller ID App Extension Information Leakage on iOS/iPadOS when Extension Disabled
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions.
7.5
CVE-2025-46290 - Remote DenialβofβService via Logic Flaw in Apple Operating Systems
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. A remote attacker may be able to cause a denial-of-service.
5.5
CVE-2026-20618 - Temporary File Handling Allows App to Access UserβSensitive Data in macOS Tahoe
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to access user-sensitive data.
3.3
CVE-2026-20663 - Information Disclosure: App Enumeration via Unfiltered Logging
The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to enumerate a user's installed apps.
5.5
CVE-2025-43417 - macOS Path Traversal Allows App Access to UserβSensitive Data
A path handling issue was addressed with improved logic. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access user-sensitive data.