Advisories
Vulnerabilities I reported, disclosed through the vendor and fixed.
2026
| CVE | Vendor | Component | Impact | CVSS | Fixed in | Advisory | Disclosed | Write-up |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20634 # | Apple | ImageIO | Processing a maliciously crafted image may result in disclosure of process memory | 3.3 | macOS Tahoe 26.3 | ZDI-26-175 | February 11, 2026 | — |
| CVE-2026-20675 # | Apple | ImageIO | Processing a maliciously crafted image may lead to disclosure of user information | 7.8 | macOS Tahoe 26.3 | ZDI-26-174 | February 11, 2026 | — |