Security Database Used by Apple Goes Independent After Funding Cut [Updated]

Update: Following the CVE Foundation's announcement (below), CISA has said the U.S. government is extending funding to ensure no continuity issues with the critical Common Vulnerabilities and Exposures (CVE) program (via Bleeping Computer). Original story follows.


Apple, along with other tech companies, relies on the Common Vulnerabilities and Exposures (CVE) program to identify and track security flaws in its software. This critical cybersecurity resource now faces an uncertain future, after federal funding was today abruptly cut off.

bug security vulnerability issue fix larry
In response to the crisis, a coalition of longtime CVE Board members announced today the formation of the CVE Foundation, a non-profit organization dedicated to ensuring the continued operation of the vulnerability identification system.

"CVE, as a cornerstone of the global cybersecurity ecosystem, is too important to be vulnerable itself," said Kent Landfield, an officer of the newly formed Foundation. "Cybersecurity professionals around the globe rely on CVE identifiers and data as part of their daily work—from security tools and advisories to threat intelligence and response. Without CVE, defenders are at a massive disadvantage against global cyber threats."

The CVE program provides a standardized system for identifying and cataloging security vulnerabilities across all software and hardware, including Apple's macOS, iOS, iPadOS, and other products. When security researchers discover flaws, they're assigned unique CVE identifiers that allow companies like Apple to coordinate patches and updates.

MITRE Corporation, which has managed the program under contract with the U.S. Department of Homeland Security, confirmed that government funding expired on April 16. Reuters reports that the expiry may be linked to the federal government undergoing a radical downsizing driven in part by the Department of Government Efficiency (DOGE). The U.S. Cybersecurity and Infrastructure Security Agency (CISA), which is exposed to the downsizing, stated it is "urgently working to mitigate impact," as the sudden funding gap threatened to disrupt vulnerability management worldwide.

Security experts warned that without CVE, cybersecurity efforts would face "total chaos" as the common language used to communicate about vulnerabilities would effectively disappear. One researcher compared it to "suddenly deleting all dictionaries."

The newly established CVE Foundation aims to transition the program to a dedicated non-profit model that isn't dependent on a single government sponsor. The Foundation's organizers revealed they had been preparing for this possibility for the past year.

"For the international cybersecurity community, this move represents an opportunity to establish governance that reflects the global nature of today's threat landscape," the Foundation stated in its announcement.

The funding cut also affects the related Common Weakness Enumeration (CWE) program, which helps companies like Apple identify potential security issues before they become vulnerabilities.

The CVE Foundation is expected to release more details about its structure and funding plans in the coming days. Apple and other major tech companies will likely play a significant role in supporting it as a critical part of cybersecurity infrastructure.

Note: Due to the political or social nature of the discussion regarding this topic, the discussion thread is located in our Political News forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Popular Stories

iPhone Pocket Short

iPhone Pocket is Now Completely Sold Out Worldwide

Tuesday November 25, 2025 7:16 am PST by
Apple recently teamed up with Japanese fashion brand ISSEY MIYAKE to create the iPhone Pocket, a limited-edition knitted accessory designed to carry an iPhone. However, it is now completely sold out in all countries where it was released. iPhone Pocket became available to order on Apple's online store starting Friday, November 14, in the United States, France, China, Italy, Japan, Singapore, ...
New Intel Logo

Apple and Intel Rumored to Partner on Mac Chips Again in a New Way

Friday November 28, 2025 7:33 am PST by
While all Macs are now powered by Apple's custom-designed chips, a new rumor claims that Apple may rekindle its partnership with Intel, albeit in a new and limited way. Apple supply chain analyst Ming-Chi Kuo today said Intel is expected to begin shipping Apple's lowest-end M-series chip as early as mid-2027. Kuo said Apple plans to utilize Intel's 18A process, which is the "earliest...
iphone black friday gold

The Best Black Friday iPhone Deals Still Available

Friday November 28, 2025 6:24 am PST by
Cellular carriers have always offered big savings on the newest iPhone models during the holidays, and Black Friday 2025 sales have kicked off at AT&T, Verizon, T-Mobile, and more. Right now we're tracking notable offers on the iPhone 17, iPhone 17 Pro, iPhone 17 Pro Max, and iPhone Air. For even more savings, keep an eye on older models during the holiday shopping season. Note: MacRumors is...
apple store down feature

Here's Why the Apple Store is Going Down

Thursday November 27, 2025 1:01 pm PST by
Apple's online store is going down for a few hours on a rolling country-by-country basis right now, but do not get your hopes up for new products. Apple takes its online store down for a few hours ahead of Black Friday every year to tease/prepare for its annual gift card offer with the purchase of select products. The store already went down and came back online in Australia and New Zealand, ...
streaming black friday 2025

Best Black Friday Streaming Deals - Save Big on Apple TV, Disney+, Hulu, and More

Thursday November 27, 2025 1:14 pm PST by
We've been focusing on deals on physical products over the past few weeks, but Black Friday is also a great time of year to purchase a streaming membership. Some of the biggest services have great discounts for new and select returning members this week, including Apple TV, Disney+, Hulu, Paramount+, Peacock, and more. Note: MacRumors is an affiliate partner with some of these vendors. When...
Cyber Monday Deals 2025

Best Cyber Monday Apple Deals Include Big Discounts on AirPods, Apple Watch, and More

Sunday November 30, 2025 7:33 am PST by
Cyber Monday is here, and you can find popular Apple products like AirPods, iPad, Apple Watch, and more at all-time low prices. In this article, the majority of the discounts will be found on Amazon. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running....
iphone air camera

iPhone Air Flop Sparks Industry Retreat From Ultra-Thin Phones

Thursday November 27, 2025 3:14 am PST by
Apple's disappointing iPhone Air sales are causing major Chinese mobile vendors to scrap or freeze their own ultra-thin phone projects, according to reports coming out of Asia. Since the ‌iPhone Air‌ launched in September, there have been reports of poor sales and manufacturing cuts, while Apple's supply chain has scaled back shipments and production. Apple supplier Foxconn has...
maxresdefault

The MacRumors Show: Apple's Big Plans for iPad Mini 8

Friday November 28, 2025 8:39 am PST by
On this week's episode of The MacRumors Show, we talk through the latest rumors about Apple's upcoming iPad mini 8. Subscribe to The MacRumors Show YouTube channel for more videos The next-generation version of the iPad mini is expected to feature an OLED display, as part of Apple's plan to expand the display technology across many more of its devices. Apple's first OLED device was the Apple...

Top Rated Comments

arkitect Avatar
8 months ago

MITRE Corporation, which has managed the program under contract with the U.S. Department of Homeland Security, confirmed that government funding expired on April 16. Reuters reports ('https://www.reuters.com/technology/us-funding-running-out-critical-cyber-vulnerability-database-manager-says-2025-04-15/') that the expiry may be linked to the federal government undergoing a radical downsizing driven in part by the Department of Government Efficiency (DOGE). The U.S. Cybersecurity and Infrastructure Security Agency (CISA), which is exposed to the downsizing, stated it is "urgently working to mitigate impact," as the sudden funding gap threatened to disrupt vulnerability management worldwide.
Just insanity from this administration…

Who in their right minds would defund this?

Almost as if they don't think of long term knock on effects.
Score: 46 Votes (Like | Disagree)
SW3029 Avatar
8 months ago
Now you can thank Trump for your viruses and malware, too. The winning never stops!
Score: 41 Votes (Like | Disagree)
tubular Avatar
8 months ago

There is so much waste, fraud, and corruption in the US government that cutting it quickly takes broad strokes.
What’s getting cut in broad strokes is Elmo’s claims about how much waste he’s found.

And if you want to talk about corruption, have you looked at the Felon In Chief lately? He’s using his powers as POTUS like a two-bit shakedown artist.
Score: 35 Votes (Like | Disagree)
PassiveSmoking Avatar
8 months ago
Is there nothing of value that these idiots won't try to ruin?
Score: 34 Votes (Like | Disagree)
thejadedmonkey Avatar
8 months ago
That's like de-funding the national weather service, but for computers.
Score: 32 Votes (Like | Disagree)
tubular Avatar
8 months ago
Trump likes Russian hackers. Saves him the trouble of posting war plans on Signal.
Score: 27 Votes (Like | Disagree)