CVE-2026-3776Disclosure(apple / macos)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to trigger a null pointer dereference and crash the application, resulting in denial of service.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos
  • pdf_editor
  • pdf_reader
  • windows

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
macospdf_editorpdf_readerwindows

1 version affected across 4 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-01: 2Technical Details · 2026-04-01: 204-01
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3776 📊 Severity: 5.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3776 #CVE-2026-3776 #CVE #Medium #CyberSecurity #InfoSec https://t.co/wYodtKkCqw

    Post summary

    The tweet announces CVE-2026-3776 as a medium‑severity vulnerability affecting multiple unspecified products, providing a CVSS score and linking to the NVD detail page.

    0001029
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3776 The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation miss… https://www.cve.org/CVERecord?id=CVE-2026-3776

    Post summary

    The passage offers a brief technical description of CVE‑2026‑3776 but provides no evidence of exploitation, patches, or proof of concept.

    00000118
    56.9K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appfoxitpdf_editor---
Appfoxitpdf_reader---
OSmicrosoftwindows---

Explore more