inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic
libexpat. Multiple issues were addressed by updating to version 2.2.1
Accessibility. A privacy issue was addressed by removing sensitive data.
Accessibility. This issue was addressed with improved redaction of sensitive information.
A use-after-free issue was addressed with improved memory management.
An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to gain root privileges.
App Store. A permissions issue was addressed with additional restrictions.
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.
Accessibility. A logic issue was addressed with improved checks.
An use-after-free flaw was found in the libxml component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=623378
External References:
https://googlechromereleases.blogspot.com/2016/07/stable-channel-update.html
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. The issue involves the "Wi-Fi" component. It allows remote attackers to execute arbitrary code (on the Wi-Fi chip) or cause a denial of service (memory corruption) by leveraging proximity for 802.11.
Accessibility. A permissions issue was addressed with additional restrictions.
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
Accessibility. A logic issue was addressed with improved checks.
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
Accessibility. This issue was addressed through improved state management.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may lead to kernel memory corruption.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously crafted file may lead to unexpected process termination.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.