FAIL › dossier
macos
PRODUCT· dossier confidence 20%
macOS has a recurring history of security vulnerabilities, including privilege escalation and memory corruption issues, with recent updates acknowledging contributions from AI-assisted security research. The frequency of these vulnerabilities necessitates diligent patching and security monitoring.
PROFILE
CategoryOperating SystemWhat they domacOS is a series of graphical operating systems produced by Apple Inc. It is the primary operating system for Apple's Macintosh computers, and also runs on Apple's iPad and iPhone devices.
Websitehttps://www.apple.com/macos/ ↗
SECURITY POSTURE
macOS has a history of frequent security vulnerabilities, often involving privilege escalation, out-of-bounds reads/writes, and logic issues. Recent updates have included contributions from AI-assisted security research.
Notable failures
- Use-After-Free Vulnerability (CVE-2019-8526)
- Out-of-Bounds Write Vulnerability (CVE-2022-22675)
- Out-of-Bounds Read Vulnerability (CVE-2022-22674)
- Gatekeeper Bypass (CVE-2021-30657)
- Privacy Preferences Bypass (CVE-2021-30713)
- Sandbox Escape (CVE-2026-13776, CVE-2026-13775, CVE-2026-14101, CVE-2026-13785, CVE-2026-13782, CVE-2026-13781, CVE-2026-13780)
- Deserialization Vulnerability (CVE-2026-34615)
- Heap-Based Buffer Overflow (CVE-2022-37434)
- Improper Cryptographic Signature Verification (CVE-2026-47304)
- Insufficient Authentication Security Controls (CVE-2026-35561)
Patterns: Privilege escalation; Out-of-bounds memory access; Logic flaws in security features; AI-assisted vulnerability discovery
FAILURE HISTORY · 26
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-04 | CVE-2022-22675 | high | An out-of-bounds write vulnerability in macOS Monterey allowed arbitrary kernel code execution, was actively exploited in the wild, and remains unpatched in KEV. |
| 2026-08-18 | CVE-2026-65400 | high | An unpatched macOS Screen Sharing vulnerability allowed network attackers to authenticate without valid credentials, enabling unauthorized access to systems. |
| 2021-11-03 | CVE-2021-30657 | high | A macOS logic flaw in System Preferences allowed malicious apps to bypass Gatekeeper, and the vulnerability was actively exploited in the wild. |
| 2022-04-04 | CVE-2022-22674 | high | An out-of-bounds read vulnerability in macOS Monterey allowed applications to read kernel memory, which was actively exploited in the wild. |
| 2023-04-17 | CVE-2019-8526 | high | Apple macOS Use-After-Free Vulnerability allows privilege escalation. |
| 2021-11-03 | CVE-2021-30713 | high | A macOS TCC permissions bypass vulnerability allowed malicious apps to circumvent privacy controls. |
| 2026-06-30 | CVE-2026-13775 | critical | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13785 | critical | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13781 | critical | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13780 | critical | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13776 | critical | Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-14101 | critical | Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) |
| 2026-06-30 | CVE-2026-13782 | critical | Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2023-06-14 | CVE-2023-34752 | critical | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit. |
| 2026-07-17 | CVE-2026-13448 | high | CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re |
| 2026-07-14 | CVE-2026-47304 | high | CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized |
| 2026-06-09 | CVE-2026-34691 | critical | CVE-2026-34691: Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af |
| 2026-05-28 | CVE-2026-9874 | critical | CVE-2026-9874: Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote |
| 2026-04-14 | CVE-2026-27303 | critical | CVE-2026-27303: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserializati |
| 2026-04-14 | CVE-2026-34615 | critical | CVE-2026-34615: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserializati |
| 2026-04-14 | CVE-2026-27246 | critical | CVE-2026-27246: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cro |
| 2026-04-14 | CVE-2026-27245 | critical | CVE-2026-27245: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro |
| 2026-04-14 | CVE-2026-27243 | critical | CVE-2026-27243: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro |
| 2026-04-03 | CVE-2026-35561 | high | CVE-2026-35561: Insufficient authentication security controls in the browser-based authenticatio |
| 2026-02-11 | CVE-2026-20677 | critical | CVE-2026-20677: A race condition was addressed with improved handling of symbolic links. This is |
| 2022-08-05 | CVE-2022-37434 | critical | CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in infl |
DOSSIER SOURCES
- Macos CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Apple security releases - Apple Support · support.apple.com
- Apple Patches 30+ Flaws as AI Systems Earn WebKit CVE Credit · dailysecurityreview.com
Open questions: What is Apple's current patching cadence for macOS vulnerabilities? · What are the root causes of the recurring vulnerability patterns? · What security controls are in place to prevent similar vulnerabilities in the future?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-08 04:07:35.051951+00:00