Skip to content
Threat Feed

CPE

Cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

9 briefs RSS
medium advisory

Denial of Service Vulnerability in Red Hat Enterprise Linux opentelemetry-collector

A vulnerability in the opentelemetry-collector package within Red Hat Enterprise Linux allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting monitoring and telemetry data collection services.

opentelemetry-collector vulnerability denial-of-service
1t 1c
high advisory

Remote Code Execution Vulnerability in WebKitGTK

A memory corruption vulnerability in WebKitGTK allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial-of-service condition by processing maliciously crafted web content.

WebKitGTK vulnerability rce linux
1t 1c
high advisory

Malicious Packagist Composer Themes Deploying iOS Spyware

Threat actors are distributing 13 malicious Composer themes via Packagist to compromise streaming websites and deploy a WebKit-to-kernel exploit chain against iOS visitors for data exfiltration and cryptocurrency wallet theft.

iOS +1 supply-chain mobile-malware web-security cryptocurrency-theft spyware
4t 2c 1i
critical advisory

Vulnerabilities in Nokogiri Vendored libxml2 and libxslt Libraries

Nokogiri versions prior to 1.13.2 bundle vulnerable libxml2 2.9.12 and libxslt 1.1.34 libraries, exposing applications to denial of service, memory disclosure, and potential code execution.

Nokogiri +2 vulnerability memory-corruption libxslt
3c
medium advisory

Remote Code Execution Vulnerability in zlib

A memory corruption vulnerability in the zlib library allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial of service.

zlib
1t 1c
high threat

Multiple Vulnerabilities in Apple macOS Tahoe

Multiple memory management and web content processing vulnerabilities in Apple macOS Tahoe version 26.6.2 could allow attackers to trigger system crashes or exfiltrate sensitive memory data.

exploited macOS Tahoe
1c
high advisory

Cross-Site Scripting Vulnerability in IBM App Connect Enterprise

IBM App Connect Enterprise contains a vulnerability, identified as CVE-2024-44280, that allows a remote, anonymous attacker to execute Cross-Site Scripting (XSS) attacks within the context of the affected application.

App Connect Enterprise xss web-vulnerability vulnerability remote-code-execution ibm security-advisory
1t 1c updated
high advisory

Apple Security Updates — July 2026

Roundup of Apple security advisories published in July 2026.

PoC macOS LaunchAgents +46 roundup
4c 10i updated
critical threat

CVE-2024-23222 Apple Safari Type Confusion Leading to Sandbox Escape

A type confusion vulnerability exists in Apple Safari, as detailed in CVE-2024-23222. A public exploit demonstrates successful exploitation of the vulnerability on iOS 16.4.1, leading to a sandbox escape, which has been patched in iOS 17.3 and macOS 14.3.

Safari cve-2024-23222 type-confusion sandbox-escape webkit
2r 2t 1c 1i