Apple Products Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple unspecified vulnerabilities affecting Apple products.
- Who is affected
- Various Apple products and versions are affected; specific products and versions are not detailed.
- Urgency
- Unknown; severity and exploitability are not specified.
- Action
- Consult Apple security updates for the specific products and versions affected by CVE-2026-3783, CVE-2026-3784, CVE-2026-4424, CVE-2026-28947, CVE-2026-28958, CVE-2026-28973, CVE-2026-28979, and CVE-2026-28984 for applicable patches.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.hkcert.org/security-bulletin/apple-products-multiple-vulnerabilities_20260818
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-37830.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-37840.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-44240.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289470.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289580.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289730.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289790.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289840.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289900.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289960.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS, iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Apple products (August 18, 2026)cert-fr-avis
- mediumCVE-2026-43795: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, i…nvd
- highCVE-2026-43794: A memory corruption issue was addressed with improved memory handling. This issue is fixed in …nvd
- mediumCVE-2026-43667: A reachable assertion was addressed with improved input validation. This issue is fixed in iOS…nvd
- mediumCVE-2026-28984: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and …nvd
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Tenable Security Center (August 14, 2026)cert-fr-avis
- medium[UPDATE] [medium] libarchive: Multiple vulnerabilities allow information disclosure and DoScert-bund
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
More from HKCERT Security Bulletins
- unknownMozilla Products Multiple Vulnerabilities2026-08-19
- unknownGoogle Chrome Multiple Vulnerabilities2026-08-19
- unknownGitLab Multiple Vulnerabilities2026-08-19
- unknownOracle Products Multiple Vulnerabilities2026-08-19
- unknownMicrosoft Edge Multiple Vulnerabilities2026-08-17