A public proof-of-concept (PoC) has been released for CVE-2026-39875, a macOS vulnerability in the Common UNIX Printing System (CUPS) that allows an unprivileged local user to perform arbitrary file writes with root privileges. The flaw affects macOS Sonoma, Sequoia,...
A newly disclosed vulnerability in the OpenAI Codex desktop application for macOS could allow attackers to exploit indirect prompt injection techniques to exfiltrate sensitive data, according to a recent entry in the GitHub Advisory Database.
Tracked as CVE-2026-14898, the issue...
PamStealer is a newly identified macOS infostealer that disguises itself as the popular open-source clipboard manager “Maccy” while silently harvesting sensitive user data.
Discovered by Jamf Threat Labs, the malware uses a stealthy two-stage infection chain designed to evade detection...
Apple has introduced a new security mechanism in the macOS Tahoe 26.4 release candidate to protect users against social engineering campaigns known as ClickFix attacks.
Discovered by users testing the latest OS build and highlighted in a popular Reddit post...
A newly discovered vulnerability is challenging the long-held belief that macOS systems are inherently immune to malware.
Security researchers from Kaspersky's Global Research and Analysis Team (GReAT) have identified a critical flaw that allows threat actors to execute malicious code...
A critical privilege escalation vulnerability has been discovered in the IPVanish VPN application for macOS. This flaw allows any unprivileged local user to execute arbitrary code as root without requiring user interaction.
The security failure completely bypasses macOS security features,...
Cybersecurity researchers have discovered a new variant of the MacSync malware targeting macOS users.
Unlike previous versions that relied on complex ClickFix techniques, this iteration masquerades as a legitimately signed, notarised Apple application, thereby bypassing macOS Gatekeeper security and...
A critical vulnerability in macOS allows attackers to escalate privileges to root access through misconfigured daemon services.
The vulnerability, dubbed "Daemon Ex Plist," exploits weaknesses in how macOS handles service property list (plist) files and has been found to affect...
The notorious Atomic macOS Stealer (AMOS) malware has received a dangerous upgrade that significantly escalates the threat to Mac users worldwide.
For the first time, this Russia-affiliated stealer is being deployed with an embedded backdoor, allowing attackers to maintain...
Multiple vulnerabilities in macOS SMBClient that could allow attackers to execute arbitrary code remotely and crash systems.
The vulnerabilities affecting the SMB filesystem client used for mounting remote file shares represent a significant security risk, as SMB has been the...