|
Reference:
CVE-2026-43726
|
Use-after-free in WebKit
WebKit · Bug 313857
|
State: Fixed
iOS 26.5.2
|
|
Reference:
CVE-2026-43663
|
Memory handling issue in WebKit
WebKit · Bug 312781
|
State: Fixed
iOS 26.5.2
|
|
Reference:
CVE-2026-43707
|
Memory corruption in WebKit
WebKit · Bug 315951
|
State: Fixed
iOS 26.5.2
|
|
Reference:
-
|
Out-of-bounds write in glTF JOINTS accessor import
ModelIO / libusd_ms
|
State: Fixed
iOS / macOS 26.6
|
|
Reference:
CVE-2026-64763
|
Out-of-bounds write in variable-topology geometry deformer source expansion
SceneKit
|
State: Fixed
iOS / macOS 26.6
|
|
Reference:
CVE-2026-64765
|
Out-of-bounds write in keyframe animation accessor deserialization
SceneKit
|
State: Fixed
iOS / macOS 26.6
|
|
Reference:
CVE-2026-64764
|
Out-of-bounds read in compressed SCNMorpher AnimCodec adjacency parsing
SceneKit
|
State: Fixed
iOS / macOS 26.6
|
|
Reference:
CVE-2026-64766
|
Out-of-bounds write in SCNParticleSystem stream allocation
Quick Look / SceneKit
|
State: Fixed
iOS / macOS 26.6
|
|
Reference:
CVE-2026-64770
|
Out-of-bounds write in USD Skel blend-shape point-index handling
libusd_ms
|
State: Fixed
iOS / macOS 26.6
|
|
Reference:
CVE-2026-64768
|
Out-of-bounds read in PointInstancer protoIndices rendering
libusd_ms
|
State: Fixed
iOS / macOS 26.6
|
|
Reference:
CVE-2026-64769
|
Out-of-bounds read in GeomSubset face-index parsing
libusd_ms
|
State: Fixed
iOS / macOS 26.6
|
|
Reference:
CVE-2026-64774
|
Out-of-bounds write in USD NURBS patch topology construction
libusd_ms
|
State: Fixed
iOS / macOS 26.6
|