惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
博客园_首页
博客园 - 【当耐特】
V
Visual Studio Blog
博客园 - 叶小钗
月光博客
月光博客
美团技术团队
J
Java Code Geeks
小众软件
小众软件
Y
Y Combinator Blog
博客园 - Franky
Martin Fowler
Martin Fowler
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
IT之家
IT之家
MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
Microsoft Security Blog
Microsoft Security Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
阮一峰的网络日志
阮一峰的网络日志
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
云风的 BLOG
云风的 BLOG

Full Disclosure

Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver [NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure Full Disclosure: Subject: Advisory Submission: EZ Game Booster Full Disclosure: CVE-2026-56877 - Skillable SCORM userId authorisation bypass Full Disclosure: [REVIVE-SA-2026-003] Revive Adserver Vulnerabilities Full Disclosure: OPNsense XPATH Injection (CVE-2026-53582) Authentication Bypass for SafeLine SL6 and SL6+ confidentiality and anonymity leakage to third parties Full Disclosure: OpenBlow Multiple Deanonymization Vulnerabilities Site-access password exposed in web server access logs via GET query string Full Disclosure: APPLE-SA-06-29-2026-3 Safari 26.5.2 Full Disclosure: APPLE-SA-06-29-2026-2 macOS Tahoe 26.5.2 APPLE-SA-06-29-2026-1 iOS 26.5.2 and iPadOS 26.5.2 symlink following and TOCTOU in privileged upload handler allow arbitrary file write as root [KIS-2026-12] Control Web Panel <= 0.9.8.1224 (userRes) SQL Injection Vulnerability Full Disclosure: [fulldis] CVE-2026-58451 - Horde Groupware IMP path traversal vuln Full Disclosure: Samsung Galaxy Buds – Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption (Vendor Response: Working as Intended) Full Disclosure: Asterisk Security Release 23.4.1 Full Disclosure: Asterisk Security Release 22.10.1 Full Disclosure: Asterisk Security Release 21.12.3 Full Disclosure: Asterisk Security Release 20.20.1 Certified Asterisk Security Release certified-22.8-cert3 Certified Asterisk Security Release certified-20.7-cert11 Zig std.http chunked reader integer overflow -> unauthenticated remote DoS Remote Kernel Stack Disclosure via MPLS Label Stack Over-read Full Disclosure: OpenBSD sppp_pap_input: PAP authentication bypass Full Disclosure: SEC Consult SA-20260618-0 :: Hardcoded Root Cloud Credentials in Application Binaries in Silver Leaf Technologies Full Disclosure: SEC Consult SA-20260617-1 :: Multiple Vulnerabilities in Quanos Content Solutions Multiple Critical Vulnerabilities in Sprecher Automation SPRECON-E-C/-E-P/-E-T3 Full Disclosure: SEC Consult SA-20260616-0 :: Broken Access Control in syracom AG Secure Login (2FA) for Atlassian Jira / Confluence
APPLE-SA-04-22-2026-2 iOS 18.7.8 and iPadOS 18.7.8
2026-04-30 · via Full Disclosure
fulldisclosure logo

Full Disclosure mailing list archives


From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Wed, 22 Apr 2026 12:13:49 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-04-22-2026-2 iOS 18.7.8 and iPadOS 18.7.8

iOS 18.7.8 and iPadOS 18.7.8 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/127003.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Notification Services
Available for: iPhone XR, iPhone XS, iPhone XS Max, iPhone 11 (all
models), iPhone SE (2nd generation), iPhone 12 (all models), iPhone 13
(all models), iPhone SE (3rd generation), iPhone 14 (all models), iPhone
15 (all models), iPhone 16 (all models), iPhone 16e, iPad mini (5th
generation - A17 Pro), iPad (7th generation - A16), iPad Air (3rd - 5th
generation), iPad Air 11-inch (M2 - M3), iPad Air 13-inch (M2 - M3),
iPad Pro 11-inch (1st generation - M4), iPad Pro 12.9-inch (3rd - 6th
generation), and iPad Pro 13-inch (M4)
Impact: Notifications marked for deletion could be unexpectedly retained
on the device
Description: A logging issue was addressed with improved data redaction.
CVE-2026-28950

This update is available through iTunes and Software Update on your iOS
device, and will not appear in your computer's Software Update
application, or in the Apple Downloads site. Make sure you have an
Internet connection and have installed the latest version of iTunes from
https://www.apple.com/itunes/

iTunes and Software Update on the device will automatically check
Apple's update server on its weekly schedule. When an update is
detected, it is downloaded and the option to be installed is presented
to the user when the iOS device is docked. We recommend applying the
update immediately if possible. Selecting Don't Install will present the
option the next time you connect your iOS device.

The automatic update process may take up to a week depending on the day
that iTunes or the device checks for updates. You may manually obtain
the update via the Check for Updates button within iTunes, or the
Software Update on your device.

To check that the iPhone, iPod touch, or iPad has been updated:

* Navigate to Settings
* Select General
* Select About. The version after applying this update
will be "iOS 18.7.8 and iPadOS 18.7.8".

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmnpFugACgkQ4Ifiq8DH
7PViuQ/6A7fJLlPcOq4KCj9px9/OoFv6mVVDd1JIyll7ybiekv1JJ89aHY85mPCV
aSChn/cEC3g/HS9d6dtYUINqQ1CWTLsQ6Ic7qW94+e0H2wlw/MzQpp+0BzqR1v7L
H4loAeBJjcWfLTs1GMi4TonLPmDFJRvqPlPeowaStqOnhYRF5EygILSMQug0vfAt
l8QJE3+ul1cssWuxUDO4RGmEeHcGZXyqg+adR5FG/K7r3FKIfE7xql5wxqjdYCO3
kfyg9phS1n0o9Wei6RUe5TzP7t0sBH68zcqrpHfr5WY4KtuMSil3qlqaok+KlA5k
bst7vN643+ilEqp2hnkc0mKpj7QdEUn/F30xl6NUoW45s1oK9qZRrQpaQnDzrYt+
3cCEnjpY9RTiobvE6U1PmriObIQwKxDTxQcRNeus/6hN8qHsowvW0AGrFm8HyhRC
R6bdyXZPpyAtPa5NZmml9T3cj3ZAa1qhceamgBfGwpB96kebCShoErpa+e56Uy6z
Rjbdz8J9Y+n3ogfNegiV8IFCo/x08x63xAqIMh+hKn786i04VCuGchfSI7PS8zMf
t33BElZ4LeSWzjYvwWFzK2jyMJKaARA6gNP1QXcka3tdnMBw4O28iW4E3vZ2r6B8
AJdh0BSUP0APnwhVLmTYO7k/XUuQ3R6Xq2MpjU0yJ/XSWei62hU=
=ETWt
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread:

  • APPLE-SA-04-22-2026-2 iOS 18.7.8 and iPadOS 18.7.8 Apple Product Security via Fulldisclosure (Apr 29)