A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. A privacy issue was addressed by removing sensitive data.
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. An inconsistent user interface issue was addressed with improved state management.
Accessibility. A privacy issue was addressed by removing sensitive data.
802.1X. An authentication issue was addressed with improved state management.
802.1X. An authentication issue was addressed with improved state management.
802.1X. An authentication issue was addressed with improved state management.
Accessibility. This issue was addressed through improved state management.
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315161
Accessibility. This issue was addressed through improved state management.
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may cause unexpected Safari crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313691
A path handling issue was addressed with improved validation.
Impact: maliciously crafted web content may disclose sensitive user information
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313085
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313693
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313857
Accounts Framework. This issue was addressed with improved data protection.
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may cause unexpected Safari crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313175