Apple adds new CVE details to several macOS, iOS, iPadOS, visionOS, and watchOS updates, old and new
Apple updated security pages for several OS releases with new CVE details, including fixes tied to privacy, data access, and privilege issues.
Intelligence analysis by GPT-5.4 Mini

Apple quietly expanded the security notes for multiple older and newer releases across its platforms, adding CVE references and more detail about the fixes. The updates cover issues ranging from private browsing access to fingerprinting, data exposure, and potential root access.
Apple went back and added more labels to some of its security fixes. Those labels help people know exactly which bugs were fixed and where they were found.
Some of the bugs were about private information, like a web browsing tab that should stay hidden unless someone unlocks it. Others were about apps learning too much, or even getting more power than they should.
It is like putting clear stickers on repaired parts of a bicycle. The bike was already fixed, but now everyone can see which parts were replaced and why.
Analysis
What Apple changed
Apple updated the security content pages for several releases across macOS, iOS, iPadOS, visionOS, and watchOS, adding CVE details that were not previously listed. The story focuses on the documentation change itself, not a brand-new software release.
Notable issues now documented
For iOS 26 and iPadOS 26, Apple added a Siri-related fix affecting private browsing tabs. The company says the issue could let tabs be accessed without authentication, and it was addressed through improved state management. Apple also added new entries for visionOS 26 and watchOS 26, including Calendar and Kernel items, with acknowledgments to external researchers.
On macOS Sonoma 14.8, Apple added several CVEs across different components. Those include a Call History issue that could allow app fingerprinting, two CoreServices bugs involving protected file-system areas and sensitive user data, a FaceTime issue where incoming calls could appear or be accepted on a locked Mac, a Phone logging issue tied to data exposure, and a StorageKit problem that could allow root privileges. Apple also added a SQLite CVE to macOS Sonoma 14.8.2, describing it as a memory-corruption issue in open-source code used by Apple software.
For iOS 18.7 and iPadOS 18.7, Apple added a Call History CVE with the same fingerprinting impact, plus an ImageIO acknowledgment entry. Overall, the update is a documentation expansion that makes Apple’s security fixes easier to track by CVE.
Key points
- Apple added new CVE details to multiple security update pages across its platforms.
- The updates cover older and newer releases, including macOS Sonoma, iOS, iPadOS, visionOS, and watchOS.
- Documented issues include private browsing access, app fingerprinting, data exposure, and a root-privilege risk.
- Apple also added acknowledgments for outside researchers on several of the fixes.



