Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,871 CVEs affect a tracked app or OS (all severities, macOS). 102 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,871
Actively exploited
102
Publication window
2004-07-27 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,871 entries macOS Hide N/A Clear all
CVE
CVE-2026-28900
MEDIUM 5.5

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciousl…

CVE-2026-28896
HIGH 7.7

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe …

CVE-2026-28849
MEDIUM 5.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP arc…

CVE-2026-20672
MEDIUM 5.5

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.…

CVE-2026-16807
HIGH 8.8

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pag…

CVE-2026-16806
HIGH 8.8

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.…

CVE-2026-16805
HIGH 8.8

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. …

CVE-2026-16804
HIGH 8.3

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sa…

CVE-2026-16424
CRITICAL 9.6

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially per…

CVE-2026-16423
HIGH 8.8

Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially e…

CVE-2026-16422
HIGH 7.5

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network positio…

CVE-2026-16421
HIGH 8.8

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr…

CVE-2026-16420
HIGH 8.8

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pag…

CVE-2026-16419
CRITICAL 9.6

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via…

CVE-2026-16418
HIGH 8.8

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pa…

CVE-2026-16417
LOW 3.1

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data…

CVE-2026-16416
CRITICAL 9.3

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network …

CVE-2026-16415
MEDIUM 5.4

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibo…

CVE-2026-16414
HIGH 7.8

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox esc…

CVE-2026-16413
HIGH 8.3

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform…

CVE-2026-15905
HIGH 7.8

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium…

CVE-2026-15904
HIGH 8.8

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to p…

CVE-2026-15903
HIGH 8.8

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

CVE-2026-15902
HIGH 8.8

Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (…

CVE-2026-15901
CRITICAL 9.6

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (C…

CVE-2026-15900
CRITICAL 9.6

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

CVE-2026-15899
CRITICAL 9.6

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted…

CVE-2026-15778
MEDIUM 6.5

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer pr…

CVE-2026-15777
HIGH 7.5

Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to pote…

CVE-2026-15776
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

CVE-2026-15775
MEDIUM 6.5

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Ch…

CVE-2026-15774
HIGH 8.3

Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a san…

CVE-2026-15773
CRITICAL 9.6

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML…

CVE-2026-15772
HIGH 8.3

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially per…

CVE-2026-15771
MEDIUM 5.3

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the rende…

CVE-2026-15770
MEDIUM 6.5

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via …

CVE-2026-15769
HIGH 8.3

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had comprom…

CVE-2026-15768
MEDIUM 6.5

Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted…

CVE-2026-15767
HIGH 8.8

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a c…

CVE-2026-15766
MEDIUM 6.5

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory vi…

CVE-2026-15765
HIGH 7.5

Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentiall…

CVE-2026-15764
HIGH 7.5

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to p…

CVE-2026-55949
HIGH 7.8

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55947
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55898
MEDIUM 6.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55142
MEDIUM 5.5

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-55141
HIGH 7.8

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55138
MEDIUM 5.5

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55137
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55136
HIGH 7.8

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM