Article URL: https://support.apple.com/en-us/128067 Comments URL: https://news.ycombinator.com/item?id=49081555 Points: 33 # Comments: 15

For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page. Description: An access issue was addressed with additional sandbox restrictions. Description: A parsing issue in the handling of directory paths was addressed with improved path validation. CVE-2026-64733: Rosyna Keller of Totally Not Malicious Software (paradisefacade.com) Impact: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org. Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory Description: An authorization issue was addressed with improved state management.