dCERT published multiple advisories covering Apple macOS and Apple Safari, warning of several vulnerabilities affecting desktop operating systems and the browser stack. The notices include a general macOS advisory, a Safari advisory, and a separate bulletin for macOS Sequoia, Sonoma, and Ventura, indicating that multiple supported Apple platforms are affected.
The advisories suggest organizations should review Apple security updates for impacted systems and prioritize patching across macOS endpoints and Safari installations. For defenders, the overlap between operating system and browser advisories raises the risk of compromise through user-facing applications and core platform components, making timely remediation and version validation important across managed Apple fleets.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
dCERT issued advisory 2026-0838 covering multiple vulnerabilities in Apple Safari. The reference provides no additional technical details, impact information, or remediation guidance.
dCERT issued advisory 2026-0840 covering multiple vulnerabilities affecting Apple macOS. The reference provides no additional technical details, impact information, or remediation guidance.
dCERT issued advisory 2025-2306 covering multiple vulnerabilities in Apple macOS. No synopsis or further event details are provided in the reference.
dCERT issued advisory 2025-1548 covering multiple vulnerabilities in Apple Safari. The reference does not include additional details on impact, exploitation, or fixes.
dCERT issued advisory 2025-1536 covering multiple vulnerabilities affecting Apple macOS Sequoia, Sonoma, and Ventura. The reference provides no further technical details or remediation information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.