NCSC-2026-0370 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOS
Apple heeft meerdere kwetsbaarheden verholpen in iOS en iPadOS. De kwetsbaarheden betreffen diverse beveiligingsproblemen zoals authenticatiefouten, out-of-bounds schrijf- en leesfouten, use-after-free, buffer overflows, race conditions, permissie- en autorisatieproblemen, geheugenbeschadiging, informatielekken, logica- en validatiefouten, en privacy-gerelateerde zwakheden. Aanvallers kunnen deze kwetsbaarheden misbruiken om ongeautoriseerde toegang te verkrijgen tot gebruikersgegevens, systeeminstabiliteit te veroorzaken door onverwachte systeem- of applicatieafsluitingen, kernelgeheugen te lezen of te beschadigen, privileges te escaleren, sandbox-beperkingen te omzeilen, en netwerkverkeer te manipuleren. Sommige kwetsbaarheden kunnen leiden tot het uitlekken van gevoelige informatie zoals Wi-Fi-wachtwoorden, apparaatidentificatoren, en gebruikerslocaties. De problemen zijn aanwezig in kerncomponenten van de besturingssystemen en diverse subsysteemfuncties zoals bestandshandling, geheugenbeheer, authenticatieprocessen, en webcontentverwerking. De fixes zijn doorgevoerd via verbeterde validatie, strengere toegangscontroles, verbeterde geheugen- en state management, en het verwijderen van kwetsbare code.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0370
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-206830.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289660.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289680.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289690.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-436610.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-436640.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-436740.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-436840.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-436860.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-436870.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0371 [1.00] [M/H] Kwetsbaarheden verholpen in Apple macOS en Samba door Apple en Sambancsc-nl
- high[NEU] [hoch] Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstell…cert-bund
- high[UPDATE] [hoch] Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownexploitedMultiples vulnérabilités dans les produits Apple (15 septembre 2026)cert-fr-avis
- unknownCVE-2026-84513: A privacy issue was addressed with improved private data redaction for log entries. This issue…nvd
- unknownCVE-2026-84511: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed …nvd
- unknownCVE-2026-84510: A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS…nvd
- unknownCVE-2026-84507: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 a…nvd
- unknownCVE-2026-84497: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7…nvd
Recent advisories for Kwetsbaarheden verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0371 [1.00] [M/H] Kwetsbaarheden verholpen in Apple macOS en Samba door Apple en Sambancsc-nl · 2026-09-15
- unknownNCSC-2026-0347 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Azurencsc-nl · 2026-09-14
- unknownexploitedNCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Centerncsc-nl · 2026-09-12
- unknownexploitedNCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Centerncsc-nl · 2026-09-11
- unknownNCSC-2026-0366 [1.00] [M/H] Kwetsbaarheden verholpen in Arista EOSncsc-nl · 2026-09-11
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN productenncsc-nl · 2026-09-10
More from NCSC-NL Advisories
- unknownNCSC-2026-0371 [1.00] [M/H] Kwetsbaarheden verholpen in Apple macOS en Samba door Apple en Samba2026-09-15
- unknownNCSC-2026-0369 [1.00] [M/H] Kwetsbaarheid verholpen in Palo Alto Networks PAN-OS2026-09-15
- unknownNCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway2026-09-14
- unknownNCSC-2026-0347 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Azure2026-09-14
- unknownNCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-12