Advisories

Vulnerabilities I reported, disclosed through the vendor and fixed.

2026

CVE Vendor Component Impact CVSS Fixed in Advisory Disclosed Write-up
CVE-2026-20634 # Apple ImageIO Processing a maliciously crafted image may result in disclosure of process memory 3.3 macOS Tahoe 26.3 February 11, 2026
CVE-2026-20675 # Apple ImageIO Processing a maliciously crafted image may lead to disclosure of user information 7.8 macOS Tahoe 26.3 February 11, 2026