Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

16,158 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-39877
HIGH 7.8 Local

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to …

CVE-2026-39875
HIGH 7.8 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious…

CVE-2026-39874
HIGH 7.8 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious…

CVE-2026-39873
CRITICAL 9.8 Network

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a mali…

CVE-2026-28982
CRITICAL 9.8 Network

A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be …

CVE-2026-28981
HIGH 7.8 Local

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a…

CVE-2026-28973
HIGH 8.6 Local

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, m…

CVE-2026-28945
HIGH 7.1 Local

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An …

CVE-2026-28932
MEDIUM 5.5 Local

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Son…

CVE-2026-28931
HIGH 8.8 Network

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Conn…

CVE-2026-28928
CRITICAL 9.8 Network

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.…

CVE-2026-28926
HIGH 7.0 Local

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to elevate pr…

CVE-2026-28912
HIGH 7.8 Local

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.

CVE-2026-28911
CRITICAL 9.8 Network

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt mem…

CVE-2026-28900
MEDIUM 5.5 Local

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP arch…

CVE-2026-28896
HIGH 7.7 Local

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An attacker may be able to cause unexp…

CVE-2026-28849
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Ga…

CVE-2026-20672
MEDIUM 5.5 Local

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be a…

CVE-2026-16410
CRITICAL 9.8 Network 1 apps

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16409
HIGH 7.5 Network 1 apps

Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16407
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16403
MEDIUM 6.5 Network 1 apps

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16402
CRITICAL 9.8 Network 1 apps

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16401
HIGH 8.8 Network 1 apps

Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16400
HIGH 7.5 Network 1 apps

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16399
HIGH 7.5 Network 1 apps

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16398
HIGH 7.5 Network 1 apps

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16396
HIGH 8.8 Network 1 apps

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVE-2026-16393
CRITICAL 9.1 Network 1 apps

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16392
CRITICAL 9.1 Network 1 apps

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16391
HIGH 7.5 Network 1 apps

Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

CVE-2026-16390
CRITICAL 9.1 Network 1 apps

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.1…

CVE-2026-16389
CRITICAL 9.8 Network 1 apps

Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16388
CRITICAL 9.8 Network 1 apps

Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16387
CRITICAL 9.8 Network 1 apps

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVE-2026-16386
HIGH 7.5 Network 1 apps

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16385
HIGH 7.5 Network 1 apps

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16384
HIGH 7.5 Network 1 apps

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16383
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVE-2026-16382
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16381
CRITICAL 9.1 Network 1 apps

Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

CVE-2026-16380
CRITICAL 9.1 Network 1 apps

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16379
HIGH 8.8 Network 1 apps

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird…

CVE-2026-16378
HIGH 7.5 Network 1 apps

Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16377
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVE-2026-16376
HIGH 7.5 Network 1 apps

Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16375
CRITICAL 9.8 Network 1 apps

Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.1…

CVE-2026-16374
HIGH 7.5 Network 1 apps

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbir…

CVE-2026-16372
HIGH 8.8 Network 1 apps

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16371
HIGH 8.8 Network 1 apps

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.