Security Vulnerabilities
- CVEs Published In November 2025
Memory corruption while processing a GP command response.
Memory corruption while processing audio streaming operations.
Memory corruption while processing request sent from GVM.
Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.
Memory corruption while processing client message during device management.
Memory corruption when triggering a subsystem crash with an out-of-range identifier.
Information disclosure while registering commands from clients with diag through diagHal.
Memory corruption while performing encryption and decryption commands.
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to access sensitive user data.
A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences.