discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Apple adds new CVE details to several macOS, iOS, iPadOS, visionOS, and watchOS updates, old and new

Apple updated security pages for several OS releases with new CVE details, including fixes tied to privacy, data access, and privilege issues.

By Marcus Mendes·May 26·9to5mac.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Apple adds new CVE details to several macOS, iOS, iPadOS, visionOS, and watchOS updates, old and new
Image: 9to5mac.com

Apple quietly expanded the security notes for multiple older and newer releases across its platforms, adding CVE references and more detail about the fixes. The updates cover issues ranging from private browsing access to fingerprinting, data exposure, and potential root access.

Why it matters

This matters because Apple’s security pages are a primary record of what was fixed, and the added CVE detail helps users and admins track exposure more precisely. It also shows Apple continuing to patch both current and older release lines, not just the latest versions.

Apple went back and added more labels to some of its security fixes. Those labels help people know exactly which bugs were fixed and where they were found.

Some of the bugs were about private information, like a web browsing tab that should stay hidden unless someone unlocks it. Others were about apps learning too much, or even getting more power than they should.

It is like putting clear stickers on repaired parts of a bicycle. The bike was already fixed, but now everyone can see which parts were replaced and why.

Analysis

What Apple changed

Apple updated the security content pages for several releases across macOS, iOS, iPadOS, visionOS, and watchOS, adding CVE details that were not previously listed. The story focuses on the documentation change itself, not a brand-new software release.

Notable issues now documented

For iOS 26 and iPadOS 26, Apple added a Siri-related fix affecting private browsing tabs. The company says the issue could let tabs be accessed without authentication, and it was addressed through improved state management. Apple also added new entries for visionOS 26 and watchOS 26, including Calendar and Kernel items, with acknowledgments to external researchers.

On macOS Sonoma 14.8, Apple added several CVEs across different components. Those include a Call History issue that could allow app fingerprinting, two CoreServices bugs involving protected file-system areas and sensitive user data, a FaceTime issue where incoming calls could appear or be accepted on a locked Mac, a Phone logging issue tied to data exposure, and a StorageKit problem that could allow root privileges. Apple also added a SQLite CVE to macOS Sonoma 14.8.2, describing it as a memory-corruption issue in open-source code used by Apple software.

For iOS 18.7 and iPadOS 18.7, Apple added a Call History CVE with the same fingerprinting impact, plus an ImageIO acknowledgment entry. Overall, the update is a documentation expansion that makes Apple’s security fixes easier to track by CVE.

Key points

  • Apple added new CVE details to multiple security update pages across its platforms.
  • The updates cover older and newer releases, including macOS Sonoma, iOS, iPadOS, visionOS, and watchOS.
  • Documented issues include private browsing access, app fingerprinting, data exposure, and a root-privilege risk.
  • Apple also added acknowledgments for outside researchers on several of the fixes.

Originally reported at

9to5mac.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechmobilehardwarepolicy

Author

Marcus Mendes

Intelligence analysis by

GPT-5.4 Mini

Published

May 26, 2026

Source

9to5mac.com

Share

Topics

securitytechmobilehardwarepolicy

Related

More from this desk

Jul 29·engadget.com

Pokémon Pokopia's First DLC Comes To Switch 2 On August 5

Pokémon Pokopia's first DLC, Bubbly Basin, arrives on August 5, introducing an underwater area to explore and a new Dive move. The update is part of the Pokémon Pokopia Expansion Pass, which costs $35.

Jul 29·9to5google.com

Galaxy Z Fold 8 gives apps new scaling options for its large displays

Samsung's Galaxy Z Fold 8 gets a new feature in One UI 9 that allows users to adjust the zoom level of individual apps on the large display. This feature is currently in beta and can be enabled in Samsung Labs.

Jul 29·techcrunch.com

Elon Musk’s X settles multiyear legal battle with the World Federation of Advertisers

Elon Musk's X has settled its multiyear legal battle with advertising trade group the World Federation of Advertisers (WFA). The settlement ends Musk's aggressive attempt to hold advertisers legally responsible for pulling spending from X over brand safety concerns.

Jul 29·9to5google.com

Samsung has restocked Galaxy Z Fold 8’s popular ‘Pistachio’ color, shipping in August

Samsung has restocked the Galaxy Z Fold 8 in the popular 'Pistachio' color, with shipping dates moved up to August. The device was previously delayed due to a sell-out and shipping issues.