Vulnerabilities reported to Apple and assigned a CVE or acknowledged.
| CVE | Component | CVSS | Impact | Platforms |
|---|---|---|---|---|
| CVE-2026-28882 | libxpc | 4.0 | An app may be able to enumerate a user's installed apps and running processes | iOS, iPadOS, macOS, watchOS, tvOS, visionOS |
| CVE-2026-43796 | Game Center | 5.5 | An app may be able to access sensitive user data | iOS, iPadOS, macOS, watchOS, tvOS, visionOS |
| CVE-2026-43792 | Safari | 6.5 | An app may be able to access sensitive user data | macOS, Safari |
| — | Spotlight | — | Acknowledged for assistance (xattr manipulation outside app sandbox on arbitrary files) | macOS |