Pinned Loading
- CVE-2026-20687-AppleJPEGDriver-UAF
CVE-2026-20687-AppleJPEGDriver-UAF PublicCVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)
- CVE-2026-28992-IOHIDFamily-FastPathUserClient-Race-Conditions
CVE-2026-28992-IOHIDFamily-FastPathUserClient-Race-Conditions PublicUAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
- AppleKeyStore-close-UAF
AppleKeyStore-close-UAF PublicAppleKeyStoreUserClient close() UAF — PoC + diff analysis (bug found/patched by unknown third party in iOS 26.3 RC, not my discovery)
- SEP-Exhaustion-Kernel-Panic
SEP-Exhaustion-Kernel-Panic PublicSEP firmware panic via AppleKeyStore - iOS/macOS 26.x kernel vulnerability
- CVE-2026-20637-AppleSEPKeyStore-UAF
CVE-2026-20637-AppleSEPKeyStore-UAF PublicCVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)
- WebKit-UAF-ANGLE-OOB-Analysis
WebKit-UAF-ANGLE-OOB-Analysis PublicAnalysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari
Something went wrong, please refresh the page to try again.
If the problem persists, check the GitHub status page or contact support.
If the problem persists, check the GitHub status page or contact support.
Uh oh!
There was an error while loading. Please reload this page.



