Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • The Apple macOS Security Update Review  – Zero Day Initiative – Blog
AttackFeed by Joe Wagner | The Apple macOS Security Update Review  - Zero Day Initiative - Blog

The Apple macOS Security Update Review  – Zero Day Initiative – Blog

Posted on May 12, 2026 By Dustin Childs No Comments on The Apple macOS Security Update Review  – Zero Day Initiative – Blog
Attack Feeds

We’ve received some feedback from those who read the Patch Blog that they would like something similar for macOS updates. Unfortunately, Apple doesn’t schedule these for a particular day, but we can provide our thoughts and analysis on the days they do release their latest patches.

For May 2026, Apple released 82 unique CVEs across the three macOS versions: 79 for macOS Tahoe 26.5, 45 for macOS Sequoia 15.7.7, and 42 for macOS Sonoma 14.8.7. Since Apple doesn’t provide CVSS scores or other severity information, we’re left to speculate on which of these bugs is the most severe. However, there are a couple that stand out.

–              CVE-2026-28819 (Wi-Fi) stands out as the strongest candidate for the most severe as it states, “An app may be able to execute arbitrary code with kernel privileges.” The combination of arbitrary code execution at the kernel level is about as bad as it gets on a severity scale. Plus, it affects all three macOS versions (Tahoe, Sequoia, and Sonoma).

–              CVE-2026-43668 (mDNSResponder) also piques my interest since, “A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.” The remote attack vector with kernel memory corruption on all three OS versions makes this a serious one, especially since mDNSResponder is always running.

–              CVE-2026-28972 (Kernel) This one states that “An app may be able to cause unexpected system termination or write kernel memory.” An out-of-bounds write directly into kernel memory on all three OS versions. This one may also have implications in the upcoming Pwn2Own Berlin contest.

Here’s a look at all the bugs released by Apple this month:

82Unique CVEs
79macOS Tahoe 26.5
45macOS Sequoia 15.7.7
42macOS Sonoma 14.8.7

CVE ID Component Impact macOS Tahoe 26.5 macOS Sequoia 15.7.7 macOS Sonoma 14.8.7
CVE-2026-28991 Accelerate An app may be able to cause a denial-of-service Yes No No
CVE-2026-28988 Accounts An app may be able to bypass certain Privacy preferences Yes No No
CVE-2026-28959 APFS An app may be able to cause unexpected system termination Yes Yes Yes
CVE-2026-28995 App Intents A malicious app may be able to break out of its sandbox Yes No No
CVE-2026-1837 AppleJPEG Processing a maliciously crafted image may lead to a denial-of-service Yes No No
CVE-2026-28956 AppleJPEG Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory Yes Yes Yes
CVE-2026-39869 Audio Processing an audio stream in a maliciously crafted media file may terminate the process Yes Yes Yes
CVE-2026-28922 CoreMedia An app may be able to access private information Yes Yes Yes
CVE-2026-28936 CoreServices Processing a maliciously crafted file may lead to unexpected app termination Yes No Yes
CVE-2026-28918 CoreSymbolication Parsing a maliciously crafted file may lead to an unexpected app termination Yes No No
CVE-2026-28878 Crash Reporter An app may be able to enumerate a user’s installed apps No Yes No
CVE-2026-28915 CUPS An app may be able to gain root privileges Yes Yes Yes
CVE-2026-43659 FileProvider An app may be able to access sensitive user data Yes Yes Yes
CVE-2026-28923 GPU Drivers A malicious app may be able to break out of its sandbox Yes Yes Yes
CVE-2026-28925 HFS An app may be able to cause unexpected system termination or write kernel memory Yes Yes Yes
CVE-2025-43524 Icons An app may be able to break out of its sandbox No Yes Yes
CVE-2026-43661 ImageIO Processing a maliciously crafted image may corrupt process memory Yes No No
CVE-2026-28977 ImageIO Processing a maliciously crafted file may lead to unexpected app termination Yes Yes Yes
CVE-2026-28990 ImageIO Processing a maliciously crafted image may corrupt process memory Yes Yes Yes
CVE-2026-28978 Installer A malicious app may be able to break out of its sandbox Yes Yes Yes
CVE-2026-28992 IOHIDFamily An attacker may be able to cause unexpected app termination Yes Yes Yes
CVE-2026-28943 IOHIDFamily An app may be able to determine kernel memory layout Yes Yes Yes
CVE-2026-28969 IOKit An app may be able to cause unexpected system termination Yes Yes Yes
CVE-2026-43655 IOSurfaceAccelerator An app may be able to cause unexpected system termination or read kernel memory Yes No No
CVE-2026-43654 Kernel An app may be able to disclose kernel memory Yes Yes Yes
CVE-2026-28908 Kernel An app may be able to modify protected parts of the file system Yes Yes Yes
CVE-2026-28954 Kernel A maliciously crafted disk image may bypass Gatekeeper checks Yes Yes Yes
CVE-2026-28897 Kernel A local user may be able to cause unexpected system termination or read kernel memory Yes Yes Yes
CVE-2026-28952 Kernel An app may be able to cause unexpected system termination Yes Yes Yes
CVE-2026-28951 Kernel An app may be able to gain root privileges Yes Yes Yes
CVE-2026-28972 Kernel An app may be able to cause unexpected system termination or write kernel memory Yes Yes Yes
CVE-2026-28986 Kernel An app may be able to cause unexpected system termination Yes Yes Yes
CVE-2026-28987 Kernel An app may be able to leak sensitive kernel state Yes Yes Yes
CVE-2026-28983 LaunchServices A remote attacker may be able to cause a denial of service Yes No No
CVE-2026-28929 Mail Drafts Replying to an email could display remote images in Mail in Lockdown Mode Yes Yes Yes
CVE-2026-43653 mDNSResponder An attacker on the local network may be able to cause a denial-of-service Yes No Yes
CVE-2026-28985 mDNSResponder An attacker on the local network may be able to cause a denial-of-service Yes No No
CVE-2026-43668 mDNSResponder A remote attacker may be able to cause unexpected system termination or corrupt kernel memory Yes Yes Yes
CVE-2026-43666 mDNSResponder An attacker on the local network may be able to cause a denial-of-service Yes Yes Yes
CVE-2026-28941 Model I/O Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents Yes Yes No
CVE-2026-28940 Model I/O Processing a maliciously crafted image may corrupt process memory Yes Yes No
CVE-2026-28961 Network Extensions An attacker with physical access to a locked device may be able to view sensitive user information Yes No No
CVE-2026-28906 Networking An attacker may be able to track users through their IP address Yes Yes Yes
CVE-2026-28840 PackageKit An app may be able to gain root privileges No Yes Yes
CVE-2026-43656 Quick Look Parsing a maliciously crafted file may lead to an unexpected app termination Yes Yes Yes
CVE-2026-43652 Sandbox An app may be able to access protected user data Yes No No
CVE-2026-39870 SceneKit Processing a maliciously crafted image may corrupt process memory Yes Yes Yes
CVE-2026-28846 SceneKit A remote attacker may be able to cause unexpected app termination Yes Yes Yes
CVE-2026-28993 Shortcuts An app may be able to access user-sensitive data Yes Yes Yes
CVE-2026-28848 SMB A remote attacker may be able to cause unexpected system termination Yes Yes No
CVE-2026-28930 Spotlight An app may be able to access protected user data Yes No No
CVE-2026-28974 Spotlight An app may be able to cause a denial-of-service Yes Yes No
CVE-2026-28996 Storage An app may be able to access sensitive user data Yes Yes Yes
CVE-2026-28919 StorageKit An app may be able to gain root privileges Yes Yes Yes
CVE-2026-28924 Sync Services An app may be able to access Contacts without user consent Yes Yes Yes
CVE-2026-39871 TV App An app may be able to observe unprotected user data Yes Yes Yes
CVE-2026-28976 UserAccountUpdater An app may be able to gain root privileges Yes No No
CVE-2026-43660 WebKit Processing maliciously crafted web content may prevent Content Security Policy from being enforced Yes No No
CVE-2026-28907 WebKit Processing maliciously crafted web content may prevent Content Security Policy from being enforced Yes No No
CVE-2026-28962 WebKit Processing maliciously crafted web content may disclose sensitive user information Yes No No
CVE-2026-43658 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash Yes No No
CVE-2026-28905 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28847 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28904 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28955 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28903 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28953 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28902 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28901 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28913 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28883 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28958 WebKit An app may be able to access sensitive user data Yes No No
CVE-2026-28917 WebKit Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28947 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash Yes No No
CVE-2026-28946 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash Yes No No
CVE-2026-28942 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash Yes No No
CVE-2026-28971 WebKit A malicious iframe may use another website’s download settings Yes No No
CVE-2026-28944 WebRTC Processing maliciously crafted web content may lead to an unexpected process crash Yes No No
CVE-2026-28819 Wi-Fi An app may be able to execute arbitrary code with kernel privileges Yes Yes Yes
CVE-2026-28994 Wi-Fi An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Wi-Fi packets Yes Yes Yes
CVE-2026-28914 zip A maliciously crafted ZIP archive may bypass Gatekeeper checks Yes No No
CVE-2026-28920 zlib Visiting a maliciously crafted website may leak sensitive data Yes Yes Yes

We’ll continue these macOS updates if people find them useful. Stay tuned for the regularly schedule Patch Tuesday blog covering Adobe and Microsoft.

  –

Read More  – Zero Day Initiative – Blog 

Post navigation

❮ Previous Post: Attackers Combine ClickFix With PySoxy Proxying to Maintain Persistence –
Next Post: Webinar: What the Riskiest SOC Alerts Go Unanswered – and How Radiant Security Can Help  – The Hacker News ❯

You may also like

AttackFeed by Joe Wagner | The Apple macOS Security Update Review  - Zero Day Initiative - Blog
Attack Feeds
Fake Xeno and Roblox Utilities Used to Install Windows RAT, Microsoft Warns  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 1, 2026
AttackFeed by Joe Wagner | Browser Extensions Are the New AI Consumption Channel That No One Is Talking About  - The Hacker News
Attack Feeds
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About  – The Hacker News
April 10, 2026
AttackFeed by Joe Wagner | CISA credential leak raises alarms, and Capitol Hill demands answers  - CyberScoop
Attack Feeds
CISA credential leak raises alarms, and Capitol Hill demands answers  – CyberScoop
May 19, 2026
AttackFeed by Joe Wagner | Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner  - The Hacker News
Attack Feeds
Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner  – The Hacker News
March 24, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.