Research

    Explore vulnerabilities discovered by Beryllium researchers, their impact, and the public records behind each finding.

    Credited vulnerabilities

    3 CVEs. Publicly documented.

    Each entry links to Apple's security advisory and the corresponding public vulnerability record.

    • CVE-2026-43681

      AppleRAID

      macOS Sonoma, Sequoia, and Tahoe

      A local user may be able to read kernel memory

      A buffer overflow was addressed with improved bounds checking.

    • CVE-2026-28976

      UserAccountUpdater

      macOS Tahoe

      An app may be able to gain root privileges

      An information leakage was addressed with additional validation.

    • CVE-2026-39869

      Audio

      macOS Tahoe

      Processing an audio stream in a maliciously crafted media file may terminate the process

      The issue was addressed with improved memory handling.