惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

9to5Mac

Apple working on iPhone anti-snatching feature that locks the device automatically Apple rolling out new AirTag 2 firmware update DuckDuckGo sees iPhone installs spike in the US following AI announcements at Google I/O Apple Wallet’s new Digital ID feature recently added more ways to use it iPhone 18 Pro could further a design trend I’ve finally come around on May 26, 2026 – watchOS 27 rumors, more As Chinese phone market reportedly picks up steam, iPhone could be a standout winner iOS 26.6 adds new alert when you try blocking too many contacts Global Running Day Challenge coming to Apple Watch next week Apple TV’s new space-race thriller does something unique, first reviews here iPadOS 26.6 beta 1 now available, plus watchOS 26.6, tvOS 26.6, more Apple releases macOS 26.6 developer beta 1 Apple releases first iOS 26.6 beta for iPhone iOS 27’s new Siri design will look like this, per report Satellite-based internet will power inflight Wi-Fi on a lot more planes in 2027 Deals: 24GB M5 MacBook Air up to $320 off, iPhone Air MagSafe Battery 40% off, M5 MacBook Pro $1,499, more Spotify will read magazine articles to you for $2 each as it further expands beyond music Here’s everything new Apple TV has coming in June Apple’s huge MacBook Pro overhaul is coming soon, here’s what we know Apple Watch glucose monitoring project gets encouraging update Apple @ Work Podcast: The future of security training - 9to5Mac Tim Cook marks Memorial Day with annual tribute post The Virtual OS Museum is a fantastic project that lets you run Mac OS, A/UX, NeXTSTEP, more Apple says U.S. is refusing to produce federal agency documents in DOJ antitrust case Ferrari Luce EV debuts with Jony Ive-designed cockpit and familiar design cues Hopes for WWDC 2026: Health for Mac, Wallet everywhere, and other OS 27 dreams All of the best Apple Memorial Day deals: AirPods Pro 3, M5 MacBook Air $199 off, MacBook Pro, Series 11, more Anker’s 25W MagSafe 3-in-1 packs active cooling in a travel-sized design [Hands-on] Insta360 jumps on the rear iPhone screen trend with Snap monitor Report: watchOS 27 to improve heart-rate tracking; AI health coach may not debut at launch Apple Intelligence image models to boast ‘major’ visual upgrades in iOS 27: report iOS 27 could offer native integration with Google Cast and other streaming protocols Report: iOS 27 to revamp the AirPods settings UI iOS 27 to feature upgraded Camera interface and Photos app: Here’s what’s rumored Apple registers new ‘gen AI’ subdomain ahead of next month’s WWDC keynote Two affordable iPhone 17 Pro accessories worth trying Indie App Spotlight: ‘Poppy’ is a proactive AI assistant that handles what Siri still can’t Apple’s Focus filters are a great feature, but they have a glaring blind spot: group chats Insta360 jumps on the rear iPhone screen trend with Snap monitor These premium desk accessories completely upgraded my setup [Video] Hands-on: Belkin’s new 5K MagSafe battery bank offers a kickstand in a slim design Apple @ Work: Why the ClickFix campaign means it is time to kill the 90 day update deferral May 22, 2026 – Apple Music AI, hardware changes Unannounced Apple headphones revealed in FCC documents Google defends its Safari deal with Apple in antitrust ruling appeal Gemini app for Mac adding ‘Spark’ agent and voice control this summer WhatsApp is working on a centralized interface showing which contacts are online HomeKit Weekly: Why the Aqara G5 Pro remains one of the best outdoor HomeKit cameras Apple shares iPhone and Mac post-quantum cryptography code on GitHub Apple TV’s hit comedy lineup keeps growing, with big new series coming AirPods with cameras suddenly make a lot more sense after this new reveal iOS 26.5.1 could launch soon as next iPhone update iPhone 18 Pro leak reveals brand new colors that could be coming watchOS 27’s rumored new Apple Watch face has me very intrigued How to stop menu bar items being hidden behind the MacBook Pro notch How to watch the F1 Canadian Grand Prix Deals: AirPods Pro 3 Memorial Day deal back at $199, M5 MacBook Air Amazon low $199 off, iPad Air $400 off, Series 11, more Apple TV’s new Matthew McConaughey comedy series coming this fall WWDC invites, iOS 27 accessibility features, new Siri will be a ‘beta’ - 9to5Mac iOS 26.5 added new features to three popular iPhone apps Apple Intelligence 2.0 promises many new features I’m very excited for Meta has released two new apps for iPhone this month 9to5Mac Overtime 068: You were right to push back on that - 9to5Mac iOS 26 tweaks iPhone Always On Display in a way you might not like May 21, 2026 – iPhone Ultra leaks, more Apple to update App Store age ratings in Australia and Vietnam next month Review: SwitchBot Wallet Finder is an incredibly useful accessory to track your wallet with iPhone Find My Apple seeks Supreme Court review of contempt finding and injunction scope in Epic Games case Report: Apple sees Latin America iPhone shipments surge 31%, led by Mexico iOS 27 could drop support for four iPhone models Codex for Mac updated with new Appshots feature that instantly gives chat context Silo season 3’s significant character change revealed in new teaser ‘Shortcuts Playground’ lets you create shortcuts using natural langauge iPhone 18 Pro could make life-saving niche feature into everyday asset BBEdit 16 out now with in-image text search, deeper Shortcuts integration, notebook filtering, more Spotify to offer AI tool that will let subscribers remix songs and cover music Deals: M5 MacBook Air $199 off Amazon low, M3 iPad Air $400 off, iPhone 17 Pro Max, accessories, more Perplexity’s Comet AI browser for iOS upgraded with 8 major improvements OpenAI improves Codex iOS experience with turn completion alerts, new commands, more Apple Watch and AirPods health features get major new global expansions Apple TV to air first major live sporting event shot entirely on iPhone 17 Pro Security Bite: Tired of app tracking pop-ups? Here’s how to auto-deny them Next year’s iPhone Pro models to get radical new design, per leaker If your Oura smart ring detects sleep apnea, it can refer you to doctors Strava adds dedicated strength training support for sets, reps, weight, and muscle groups Brye song that hit 100M streams was produced in GarageBand on school iPad OLED MacBook Pro screens on-track amid talk of delayed launch AT&T announces new $15/month ‘Build-a-Plan’ wireless plan ACSI: Samsung edges out Apple in cell phone satisfaction, while Apple Watch ties at the top Adobe Photoshop update brings on-device AI processing, but there is a catch Eddy Cue named 2026 Cannes Lions Entertainment Person of the Year The Outsiders celebrates Apple Design Awards 2026 nomination with biggest update yet Apple TV renews ‘Knife Edge: Chasing Michelin Stars’ for a second season tvOS 27 will give Apple TV 4K a useful new display setting Kansas City Public Schools to replace 30,000 Windows PCs and Chromebooks with Apple devices Hovercraft is a new Mac app that makes video call presentations feel more personal Apple Music shares what it is doing to ‘keep music fair’ in an AI world iOS 26.5 won’t let users downgrade to prior update any longer MacBook Ultra could be very good news for MacBook Pro users Airbnb upgrades iOS and Android app with three key enhancements for your next trip
Apple adds new CVE details to several macOS, iOS, iPadOS, visionOS, and watchOS updates [U]
Marcus Mende · 2026-05-27 · via 9to5Mac

Apple today updated the security content pages for several macOS, iOS, iPadOS, visionOS, and watchOS releases, adding new CVE details for vulnerabilities addressed in each update. Here are the details.

New details for older and recent software releases

Last September, Apple released macOS 14.8 Sonoma, iOS 18.7, and iPadOS 18.7, with important security updates addressing vulnerabilities that, among other things, could let an attacker access protected or sensitive user data.

Since then, Apple updated macOS Sonoma another six times, with the system currently sitting at version 14.8.7 (the company skipped 14.8.6). Likewise, iPhone and iPad users who have not moved to newer major releases have similarly continued to receive updates, with iOS 18 and iPadOS 18 now at version 18.7.9.

For Apple Watch and Apple Vision Pro users, Apple also released watchOS 26 and visionOS 26 last year, introducing multiple new features, in addition to including important security fixes.

That said, Apple today updated the security content page for these system versions (and then some), adding more details on the fixes included and their corresponding CVEs.

Here are the security fixes added today on iOS 26 and iPadOS 26’s security content page:

Siri

Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Private Browsing tabs may be accessed without authentication
Description: This issue was addressed through improved state management.
CVE-2025-30468: Richard Hyunho Im (@richeeta), Jiwon Park

Calendar

We would like to acknowledge Keisuke Chinone (Iroiro) and Rosyna Keller of Totally Not Malicious Software for their assistance.

Here’s what Apple added to the security content of visionOS 26 and watchOS 26:

Calendar

We would like to acknowledge Keisuke Chinone (Iroiro) and Rosyna Keller of Totally Not Malicious Software for their assistance.

Kernel

We would like to acknowledge Sungwoo Kim, Yepeng Pan, Prof. Dr. Christian Rossow for their assistance.

Here are the security fixes added today on macOS Sonoma 14.8’s security content page:

Call History

Available for: macOS Sonoma
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved redaction of sensitive information.
CVE-2025-43357: Rosyna Keller of Totally Not Malicious Software, Guilherme Rambo of Best Buddy Apps (rambo.codes)

CoreServices

Available for: macOS Sonoma
Impact: An app may be able to modify protected parts of the file system
Description: A permissions issue was addressed with additional restrictions.
CVE-2025-43290: Zhongcheng Li from IES Red Team of ByteDance

CoreServices

Available for: macOS Sonoma
Impact: A malicious app may be able to access sensitive user data
Description: A logic issue was addressed with improved validation.
CVE-2025-43289: Matej Moravec (@MacejkoMoravec), Kirin (@Pwnrin)

FaceTime

Available for: macOS Sonoma
Impact: Incoming FaceTime calls can appear or be accepted on a locked macOS device, even with notifications disabled on the lock screen
Description: This issue was addressed through improved state management.
CVE-2025-31271: Shantanu Thakur

Phone

Available for: macOS Sonoma
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
CVE-2025-43508: Wojciech Regula of SecuRing (wojciechregula.blog)

StorageKit

Available for: macOS Sonoma
Impact: A malicious app may be able to gain root privileges
Description: A logic issue was addressed with improved checks.
CVE-2025-43306: Mickey Jin (@patch1t)

Here are the security fixes added today on macOS Sonoma 14.8.2’s security content page:

SQLite

Available for: macOS Sonoma
Impact: Processing a file may lead to memory corruption
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2025-6965

And here’s what Apple added to the security content of iOS 18.7 and iPadOS 18.7:

Call History

Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved redaction of sensitive information.
CVE-2025-43357: Rosyna Keller of Totally Not Malicious Software, Guilherme Rambo of Best Buddy Apps (rambo.codes)

ImageIO

We would like to acknowledge DongJun Kim (@smlijun) and JongSeong Kim (@nevul37) in Enki WhiteHat for their assistance.

To learn more about Apple’s security updates, follow this link.


Update: Apple has also updated the security content details of macOS Sequoia 15.7:

Call History

Available for: macOS Sequoia
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved redaction of sensitive information.
CVE-2025-43357: Rosyna Keller of Totally Not Malicious Software, Guilherme Rambo of Best Buddy Apps (rambo.codes)

CoreServices

Available for: macOS Sequoia
Impact: An app may be able to modify protected parts of the file system
Description: A permissions issue was addressed with additional restrictions.
CVE-2025-43290: Zhongcheng Li from IES Red Team of ByteDance

CoreServices

Available for: macOS Sequoia
Impact: A malicious app may be able to access sensitive user data
Description: A logic issue was addressed with improved validation.
CVE-2025-43289: Matej Moravec (@MacejkoMoravec), Kirin (@Pwnrin)

Crash Reporter

Available for: macOS Sequoia
Impact: An app may be able to gain root privileges
Description: A race condition was addressed with additional validation.
CVE-2025-46284: an anonymous researcher

dyld

Available for: macOS Sequoia
Impact: Visiting a website may lead to an app denial-of-service
Description: A denial-of-service issue was addressed with improved input validation.
CVE-2025-43464: Duy Trần (@khanhduytran0), @EthanArbuckle

FaceTime

Available for: macOS Sequoia
Impact: Incoming FaceTime calls can appear or be accepted on a locked macOS device, even with notifications disabled on the lock screen
Description: This issue was addressed through improved state management.
CVE-2025-31271: Shantanu Thakur

Phone

Available for: macOS Sequoia
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
CVE-2025-43508: Wojciech Regula of SecuRing (wojciechregula.blog)

StorageKit

Available for: macOS Sequoia
Impact: A malicious app may be able to gain root privileges
Description: A logic issue was addressed with improved checks.
CVE-2025-43306: Mickey Jin (@patch1t)

Additionally, Apple updated macOS Tahoe 26’s security content details:

AWD

Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed by removing the vulnerable code.
CVE-2025-43451: Noah Gregory (wts.dev)

Compression

Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
CVE-2025-43403: Mickey Jin (@patch1t)

CoreServices

Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to modify protected parts of the file system
Description: A permissions issue was addressed with additional restrictions.
CVE-2025-43290: Zhongcheng Li from IES Red Team of ByteDance

CoreServices

Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: A malicious app may be able to access sensitive user data
Description: A logic issue was addressed with improved validation.
CVE-2025-43289: Matej Moravec (@MacejkoMoravec), Kirin (@Pwnrin)

Crash Reporter

Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to gain root privileges
Description: A race condition was addressed with additional validation.
CVE-2025-46284: an anonymous researcher

GPU Drivers

Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds read was addressed with improved bounds checking.
CVE-2025-46280: Jian Lee (@speedyfriend433)

PackageKit

Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An attacker with root privileges may be able to delete protected system files
Description: This issue was addressed through improved state management.
CVE-2025-46310: Mickey Jin (@patch1t)

Sandbox

Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved restrictions.
CVE-2025-46307: Yiğit Can YILMAZ (@yilmazcanyigit) and an anonymous researcher

StorageKit

Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: A malicious app may be able to gain root privileges
Description: A logic issue was addressed with improved checks.
CVE-2025-43306: Mickey Jin (@patch1t)

Calendar

We would like to acknowledge Keisuke Chinone (Iroiro) and Rosyna Keller of Totally Not Malicious Software for their assistance.

Kernel

We would like to acknowledge Sungwoo Kim, Yepeng Pan, Prof. Dr. Christian Rossow for their assistance.

Finally, Apple added one item to the security details of tvOS 26:

Kernel

We would like to acknowledge Sungwoo Kim, Yepeng Pan, Prof. Dr. Christian Rossow for their assistance.

Worth checking out on Amazon

Add 9to5Mac as a preferred source on Google Add 9to5Mac as a preferred source on Google

FTC: We use income earning auto affiliate links. More.