About the security content of macOS Tahoe 26.7

This document describes the security content of macOS Tahoe 26.7.

About Apple security updates

For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page.

Apple security documents reference vulnerabilities by CVE-ID when possible.

For more information about security, see the Apple Product Security page.

macOS Tahoe 26.7

Released September 14, 2026

Accelerate Framework

Available for: macOS Tahoe

Impact: Processing a maliciously crafted image may lead to unexpected process termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-86882: Peter Malone

Accessibility

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with improved data protection.

CVE-2026-43664: Stuart Wallace, Rosyna Keller of Totally Not Malicious Software, Jian Lee (@speedyfriend433), Ilya Andr (andrd3v), Gongyu Ma (@Mezone0), David Strnadel, Daniel Febrero, CJ Vana, Asaf Cohen

APFS

Available for: macOS Tahoe

Impact: An application may be able to access restricted files

Description: A permissions issue was addressed with improved path validation.

CVE-2026-86910: an anonymous researcher

APFS

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination or write kernel memory

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84523: Cem Onat Karagun, an anonymous researcher

App Store

Available for: macOS Tahoe

Impact: A local app may be able to read a persistent account identifier

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-86888: Zhongcheng Li (CK01)

AppKit

Available for: macOS Tahoe

Impact: An app may be able to access protected user data

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-84587: an anonymous researcher

Apple Account

Available for: macOS Tahoe

Impact: An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account

Description: An authentication issue was addressed with improved state management.

CVE-2026-20683: Lehan Dilusha Jayasingha (Sri Lanka), Jasminder Pal Singh, Dem0ns (@天府简易信工作室), Abdelhak Kherroubi

Apple Neural Engine

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: An integer overflow was addressed with improved input validation.

CVE-2026-65408: tamdao

AppleAVD

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A use after free issue was addressed with improved memory management.

CVE-2026-65407: Franco Belman at Blackwing Intelligence

AppleDouble

Available for: macOS Tahoe

Impact: Mounting a disk image with maliciously crafted files may lead to unexpected system termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84519: Richard Zana

AppleMobileFileIntegrity

Available for: macOS Tahoe

Impact: A malicious app may be able to break out of its sandbox

Description: A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement.

CVE-2026-65381: Mickey Jin (@patch1t)

ATS

Available for: macOS Tahoe

Impact: An app may be able to read files outside of its sandbox

Description: A permissions issue was addressed by removing the vulnerable code.

CVE-2026-43763: Pavan Nallamothu, Jared Reyes

ATS

Available for: macOS Tahoe

Impact: An app may be able to access user-sensitive data

Description: A logging issue was addressed with improved data redaction.

CVE-2026-84525: D4rthL

ATS

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: A permissions issue was addressed with improved validation.

CVE-2026-65342: Mohamad Dawoud / Abodi Dawoud, Ahmed Alwardani

AuthKit

Available for: macOS Tahoe

Impact: A local app may be able to read a persistent account identifier

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-84583: Zhongcheng Li from IES Red Team

autofs

Available for: macOS Tahoe

Impact: An attacker with control of a network directory server may be able to execute arbitrary code with root privileges

Description: A path traversal issue was addressed with improved path validation.

CVE-2026-84568: Mr.Gedik (@h4ck2s3c) of Turkish Technology

autofs

Available for: macOS Tahoe

Impact: An app may be able to bypass Gatekeeper checks

Description: A logic issue was addressed with improved checks.

CVE-2026-84570: Mr.Gedik (@h4ck2s3c)

Automator

Available for: macOS Tahoe

Impact: An app may be able to break out of its sandbox

Description: An authorization issue was addressed with improved state management.

CVE-2026-84535: Sindre Sorhus, Oren Yomtov, Morris Richman (@morrisinlife), Kun Peeks (@SwayZGl1tZyyy)

AVEVideoEncoder

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: The issue was addressed with improved checks.

CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic Research

AVEVideoEncoder

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A type confusion issue was addressed with improved memory handling.

CVE-2026-84616: Peter Malone

AVEVideoEncoder

Available for: macOS Tahoe

Impact: A sandboxed app may be able to execute arbitrary code with kernel privileges

Description: A race condition was addressed with improved state management.

CVE-2026-84607: Ruslan Dautov

BackgroundAssets

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: A logic issue was addressed with improved validation.

CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security

Bluetooth

Available for: macOS Tahoe

Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-65414

cd9660

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: The issue was addressed with improved memory handling.

CVE-2026-84567: Sanny Mitra, Sihyun Roh (Compsec, SNU), ngockhanh from Cystack, 정우 하 (@0xfa11babe), Suresh Sundaram, Surej Sekhar, Kun Peeks (@SwayZGl1tZyyy), Hari Shanmugam (The Hxr1), Ataberk Yavuzer

copyfile

Available for: macOS Tahoe

Impact: An archive may be able to bypass Gatekeeper

Description: A file quarantine bypass was addressed with additional checks.

CVE-2026-65399: Rishabh Jain (rjcyber) of cyberplanet, Pasquale Scola, an anonymous researcher

Core Bluetooth

Available for: macOS Tahoe

Impact: An app may be able to access Bluetooth device information

Description: An authorization issue was addressed with improved state management.

CVE-2026-86891: Dawuge of Shuffle Team

CoreDrag

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected process termination or disclose process memory

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-43683: Nathaniel Oh (@calysteon)

CoreMedia

Available for: macOS Tahoe

Impact: An app may be able to access user-sensitive data

Description: An access issue was addressed with additional sandbox restrictions.

CVE-2026-43789: 이재영

CoreMedia

Available for: macOS Tahoe

Impact: Processing a maliciously crafted video file may lead to unexpected app termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-65344: Siyeong kim

CoreMedia

Available for: macOS Tahoe

Impact: A sandboxed process may be able to circumvent sandbox restrictions

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-86876: Chris Bailey - Short Circuit

CoreMedia Video Toolbox

Available for: macOS Tahoe

Impact: Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory

Description: The issue was addressed with improved memory handling.

CVE-2026-43702: Nathaniel Oh (@calysteon)

CoreML

Available for: macOS Tahoe

Impact: A sandboxed app may be able to access restricted files

Description: A permissions issue was addressed with improved path validation.

CVE-2026-84624: AL Najafi, tamdao

CoreMotion

Available for: macOS Tahoe

Impact: An app may be able to access motion data from headphones without user consent

Description: An authorization issue was addressed with improved validation.

CVE-2026-43737: Stuart Wallace

CoreServices

Available for: macOS Tahoe

Impact: An app may be able to bypass Privacy preferences

Description: A permissions issue was addressed with improved state management.

CVE-2026-84574: Mickey Jin (@patch1t)

CoreServices

Available for: macOS Tahoe

Impact: An app may bypass Gatekeeper checks

Description: A logic issue was addressed with improved checks.

CVE-2026-28899: Kraken Cryptocurrency Exchange, Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

CoreServices

Available for: macOS Tahoe

Impact: A malicious application may be able to access restricted files

Description: A permissions issue was addressed with improved validation.

CVE-2026-84559: Ryan Hughes

CoreServices

Available for: macOS Tahoe

Impact: An app may be able to gain root privileges

Description: This issue was addressed with additional entitlement checks.

CVE-2026-43786: Kujtim Kryeziu (Sentry)

CoreText

Available for: macOS Tahoe

Impact: Processing web content may lead to a denial-of-service

Description: A null pointer dereference was addressed with improved input validation.

CVE-2026-65412: Pavan Nallamothu

CoreTypes

Available for: macOS Tahoe

Impact: A malicious app may be able to break out of its sandbox

Description: A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement.

CVE-2026-65381: Mickey Jin (@patch1t)

CoreUI

Available for: macOS Tahoe

Impact: Processing a maliciously crafted file may lead to unexpected app termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re)

CoreUI

Available for: macOS Tahoe

Impact: Processing a maliciously crafted asset catalog may lead to unexpected process termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84511: stratan (@5tratan), Rahul Raj

CUPS

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A logic issue was addressed with improved checks.

CVE-2026-84563: Yongyue WANG AKA Brian.W of OKX security, Omar Cerrito

CUPS

Available for: macOS Tahoe

Impact: An app may be able to gain elevated privileges

Description: A path handling issue was addressed with improved validation.

CVE-2026-64790: Aaron Grattafiori - NVIDIA AI Red Team

CUPS

Available for: macOS Tahoe

Impact: A remote user may cause an unexpected app termination or arbitrary code execution

Description: A validation issue was addressed with improved input sanitization.

CVE-2026-43692: Aaron Grattafiori - NVIDIA AI Red Team

CUPS

Available for: macOS Tahoe

Impact: An attacker in a privileged network position may be able to cause a denial-of-service

Description: An integer overflow was addressed with improved input validation.

CVE-2026-84554: Meshaal @ Darkcov, Joseph Shamoon

CUPS

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved state management.

CVE-2026-84540: Yongyue WANG AKA Brian.W of OKX security, 章鱼哥@aipy (aipyaipy.com), instantraaamen (github.com/instantraaamen) Contact: masa.shiramizu@gmail.com

CUPS

Available for: macOS Tahoe

Impact: An app may be able to gain root privileges

Description: A path handling issue was addressed with improved validation.

CVE-2026-43691: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

CUPS

Available for: macOS Tahoe

Impact: Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-84516: 章鱼哥@aipy (aipyaipy.com)

CUPS

Available for: macOS Tahoe

Impact: An app may be able to gain root privileges

Description: An injection issue was addressed with improved validation.

CVE-2026-43698: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

CUPS

Available for: macOS Tahoe

Impact: An application may be able to access restricted files

Description: An input validation issue was addressed with improved input validation.

CVE-2026-84541: 章鱼哥@aipy (aipyaipy.com)

DeviceCheck

Available for: macOS Tahoe

Impact: An app may be able to read persistent device identifiers

Description: An authorization issue was addressed with improved access control.

CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill (@jjtech@infosec.exchange)

Directory Utility

Available for: macOS Tahoe

Impact: An app may be able to gain root privileges

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84505: Tommy DeVoss from Braze Security Team (@thedawgyg)

Disk Images

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: The issue was addressed with improved memory handling.

CVE-2026-84552: Tommy DeVoss from Braze Security Team (@thedawgyg), PETOWORKS의 Bugeun Choi (@Bugeun), Peter Malone, Hyunwoo Kim (@v4bel), flower xu, Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research), Adriatik Raci

Disk Images

Available for: macOS Tahoe

Impact: Processing a maliciously crafted disk image may lead to unexpected app termination

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-84565: Nathaniel Oh (@calysteon)

Disk Images

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A race condition was addressed with additional validation.

CVE-2026-84550: Hyunwoo Kim (@v4bel), Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research)

Disk Images

Available for: macOS Tahoe

Impact: An app may be able to gain root privileges

Description: This issue was addressed with improved checks.

CVE-2026-65362: Manish Bhatt, Amazon Leo Security, Nathaniel Oh (@calysteon), Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs, Adriatik Raci

Disk Images

Available for: macOS Tahoe

Impact: Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory

Description: A buffer overflow was addressed with improved bounds checking.

CVE-2026-84512: Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research)

exFAT

Available for: macOS Tahoe

Impact: Mounting a maliciously crafted volume may lead to unexpected system termination

Description: A heap buffer overflow was addressed with improved bounds checking.

CVE-2026-84510: Richard Zana, Meta Red Team X - Nik Tsytsarkin

File Bookmark

Available for: macOS Tahoe

Impact: An app may be able to modify a file it only had permission to read

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-43785: Junyeong Lee (jylab.github.io), Merrick Hare, Narendra Singh (@_3P1C), John Nzyuko Uvyu, Aditya Kumar

file_cmds

Available for: macOS Tahoe

Impact: Extracting a maliciously crafted archive may allow an attacker to write arbitrary files

Description: A path handling issue was addressed with improved validation.

CVE-2026-84534: Geoffrey Lovelace

FontParser

Available for: macOS Tahoe

Impact: Processing a maliciously crafted font file may lead to unexpected app termination

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-84524: an anonymous researcher

Foundation

Available for: macOS Tahoe

Impact: An app may be able to cause a denial of service

Description: A type confusion issue was addressed with improved memory handling.

CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research

Game Center

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: A permissions issue was addressed with improved validation.

CVE-2026-84618: Luke Symons

Graphics

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A race condition was addressed with improved state handling.

CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg), Jiyong Yang

Heimdal

Available for: macOS Tahoe

Impact: A user in a privileged network position may be able to leak sensitive user information

Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.

CVE-2022-3437: Roman Zabicki

HFS

Available for: macOS Tahoe

Impact: Mounting a malicious disk image may cause unexpected system termination

Description: A buffer overflow was addressed with improved bounds checking.

CVE-2026-28934: Arni Hardarson (Neonix Security), Tristan Madani (@TristanInSec) from Talence Security, 정우 하, Aswin Kumar Gokulakannan, Peter Malone, Dun

HFS

Available for: macOS Tahoe

Impact: Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory

Description: A buffer overflow was addressed with improved bounds checking.

CVE-2026-84581: Jonathan Bar Or (@yo_yo_yo_jbo), Feng Xue and XGPT of ThreatBook, Alfredo Pesoli (@__rev) of Bynar.io

Image Capture

Available for: macOS Tahoe

Impact: An app may be able to access user-sensitive data

Description: A path handling issue was addressed with improved validation.

CVE-2026-64756: Luke Symons

ImageIO

Available for: macOS Tahoe

Impact: Processing a maliciously crafted image may result in disclosure of process memory

Description: An uninitialized memory issue was addressed with improved memory initialization.

CVE-2026-84564: Justin O'Leary

ImageIO

Available for: macOS Tahoe

Impact: Processing a maliciously crafted image may result in memory corruption

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan

IOGPUFamily

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A race condition was addressed with improved state handling.

CVE-2026-43743: Lyutoon, Dun

IOKit

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A use after free issue was addressed with improved memory management.

CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영

Kernel

Available for: macOS Tahoe

Impact: A local attacker may be able to cause unexpected system termination or corrupt kernel memory

Description: The issue was addressed with improved memory handling.

CVE-2026-84566: Bernhard Jackiewicz

Kernel

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination or corrupt kernel memory

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-28968: Svetoslav Stolarov & Aisa Fox, Josh Maine of Calif.io, genter0, Dun

Kernel

Available for: macOS Tahoe

Impact: Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-84549: Surya Narayan Kushwaha, Aswin Kumar Gokulakannan

Kernel

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination or write kernel memory

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84619: James Duffy (@0x4A616D657344), genter0, Eddy Tsalolikhin

Kernel

Available for: macOS Tahoe

Impact: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory

Description: The issue was addressed with improved memory handling.

CVE-2026-43790: Omar Cerrito

Kernel

Available for: macOS Tahoe

Impact: An app with root privileges may be able to read uninitialized kernel memory

Description: A memory initialization issue was addressed with improved memory handling.

CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.)

Kernel

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A memory corruption issue was addressed with improved memory handling.

CVE-2026-65377: Ye Zhang (@VAR10CK) of Baidu Security, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: macOS Tahoe

Impact: A malicious application may bypass Gatekeeper checks

Description: A logic issue was addressed with improved state management.

CVE-2026-65369: an anonymous researcher

Kernel

Available for: macOS Tahoe

Impact: Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory

Description: An integer overflow was addressed with improved input validation.

CVE-2026-84544: Surya Narayan Kushwaha, Abhijeet Singh (www.linkedin.com/in/abhiunix/)

Kernel

Available for: macOS Tahoe

Impact: Connecting to a malicious NFS server may disclose kernel memory

Description: The issue was addressed with improved memory handling.

CVE-2026-43687: R4mbb of KRsecurity, Peter Malone

Kernel

Available for: macOS Tahoe

Impact: An app may be able to gain root privileges

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-86917: Hiroki Imai (LAC Co., Ltd.)

Kernel

Available for: macOS Tahoe

Impact: Connecting to a malicious NFS server may lead to kernel memory corruption

Description: A use-after-free issue was addressed with improved memory management.

CVE-2026-43686: Peter Malone

Kernel

Available for: macOS Tahoe

Impact: A remote attacker may be able to cause a denial-of-service

Description: A denial-of-service issue was addressed with improved input validation.

CVE-2026-84538: Stuart Thomas

Kernel

Available for: macOS Tahoe

Impact: A remote attacker may be able to cause unexpected system termination

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-65364: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: macOS Tahoe

Impact: An app may be able to determine kernel memory layout

Description: A memory initialization issue was addressed with improved memory handling.

CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A race condition was addressed with improved state handling.

CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security

CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

CVE-2026-65401: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: macOS Tahoe

Impact: An app may be able to disclose kernel memory

Description: An information disclosure issue was addressed with improved memory management.

CVE-2026-84530: Vladislav Shevchenko (Positive Technologies)

Kernel

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A type confusion issue was addressed with improved checks.

CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: A use after free issue was addressed with improved memory management.

CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

CVE-2026-84521: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination or corrupt kernel memory

Description: A race condition was addressed with improved state handling.

CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: An integer overflow was addressed with improved input validation.

CVE-2026-84517: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination or corrupt kernel memory

Description: A double free issue was addressed with improved memory management.

CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati

Kernel

Available for: macOS Tahoe

Impact: A local user may be able to cause unexpected system termination or read kernel memory

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kext Management

Available for: macOS Tahoe

Impact: An app may be able to modify protected parts of the file system

Description: This issue was addressed with additional entitlement checks.

CVE-2026-84514: Mohamed Wedatalla, Nathaniel Oh (@calysteon), Arjanit Isufi

Keychain Access

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved access control.

CVE-2026-84556: Peter Malone, HvxyZLF, Chris Bailey - Short Circuit, Adrián Díaz Aguilar

LaunchServices

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: A parsing issue in the handling of directory paths was addressed with improved path validation.

CVE-2026-65382: an anonymous researcher

libxpc

Available for: macOS Tahoe

Impact: An app may be able to bypass sandbox restrictions

Description: An access issue was addressed with additional sandbox restrictions.

CVE-2026-84577: Dave G. and Alex Radocea of supernetworks.org

Mail

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with improved checks.

CVE-2026-84573: Dawuge of Shuffle Team

Mail

Available for: macOS Tahoe

Impact: An attacker in a privileged network position may be able to leak sensitive user information

Description: A logic issue was addressed with improved checks.

CVE-2026-43787: Armend Gashi

Messages

Available for: macOS Tahoe

Impact: An app may be able to access protected user data

Description: A logic issue was addressed with improved state management.

CVE-2026-43741: Dawuge of Shuffle Team

MobileAccessoryUpdater

Available for: macOS Tahoe

Impact: Connecting a malicious accessory may cause unexpected system termination

Description: A memory corruption issue was addressed with improved input validation.

CVE-2026-86924: Matthew Zamat

Model I/O

Available for: macOS Tahoe

Impact: Opening a maliciously crafted file may lead to unexpected process termination

Description: A buffer overflow was addressed with improved size validation.

CVE-2026-84497: Yiğit Can YILMAZ (@yilmazcanyigit)

NetworkExtension

Available for: macOS Tahoe

Impact: An app may be able to identify what other apps a user has installed

Description: An information disclosure issue was addressed with improved state management.

CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team

NetworkExtension

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved state management.

CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos

odproxyd

Available for: macOS Tahoe

Impact: An app may be able to gain root privileges

Description: This issue was addressed with improved checks.

CVE-2026-64712: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

quarantine

Available for: macOS Tahoe

Impact: An app may be able to break out of its sandbox

Description: The issue was addressed with improved checks.

CVE-2026-84580: an anonymous researcher

quarantine

Available for: macOS Tahoe

Impact: An app may be able to break out of its sandbox

Description: A logic issue was addressed with improved checks.

CVE-2026-84578: Kenneth Chew

QuartzCore

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with improved checks.

CVE-2026-84576: Dora Orak, @Ethan Arbuckle, and @leptos_null

Quick Look

Available for: macOS Tahoe

Impact: Processing a maliciously crafted document may lead to an out-of-bounds read

Description: An integer overflow was addressed with improved input validation.

CVE-2026-84548: Peter Malone

RealityKit

Available for: macOS Tahoe

Impact: Opening a maliciously crafted file may cause unexpected process termination or disclose process memory

Description: An out-of-bounds read issue was addressed with improved input validation.

CVE-2026-84532: stratan (@5tratan), Hongsik Kim (mnur)

RealityKit

Available for: macOS Tahoe

Impact: Processing a maliciously crafted file may lead to unexpected app termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-28966: stratan (@5tratan)

Reminders

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with improved checks.

CVE-2026-65403: Rahul Raj

SceneKit

Available for: macOS Tahoe

Impact: Processing a maliciously crafted file may result in disclosure of process memory

Description: An integer overflow was addressed with improved input validation.

CVE-2026-84487: stratan (@5tratan), Peter Malone, Dhiyanesh Selvaraj (@redroot97)

SceneKit

Available for: macOS Tahoe

Impact: An app may be able to cause a denial of service

Description: An integer overflow was addressed with improved input validation.

CVE-2026-65413: Peter Malone

SceneKit

Available for: macOS Tahoe

Impact: Processing a maliciously crafted 3D model may lead to memory corruption

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter Malone

CVE-2026-84611: Nathaniel Oh (@calysteon)

SceneKit

Available for: macOS Tahoe

Impact: Processing a maliciously crafted 3D model may lead to memory corruption

Description: The issue was addressed with improved memory handling.

CVE-2026-84632: Peter Malone

SceneKit

Available for: macOS Tahoe

Impact: Processing a maliciously crafted 3D model may lead to memory corruption

Description: An integer overflow was addressed with improved input validation.

CVE-2026-84620: Peter Malone

SceneKit

Available for: macOS Tahoe

Impact: Processing a maliciously crafted 3D file may lead to an out-of-bounds read

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-43697: Peter Malone

SceneKit

Available for: macOS Tahoe

Impact: Processing a maliciously crafted 3D scene may lead to unexpected process termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84526: stratan (@5tratan)

Screen Sharing Server

Available for: macOS Tahoe

Impact: An app may be able to access user-sensitive data

Description: An access issue was addressed with improved access restrictions.

CVE-2026-43760: Alfredo Pesoli (@__rev) of Bynar.io, wdszzml and Atuin Automated Vulnerability Discovery Engine

Screen Sharing Server

Available for: macOS Tahoe

Impact: An attacker on the network may be able to authenticate to Screen Sharing without valid credentials

Description: An authentication issue was addressed with improved state management.

CVE-2026-65400: Alfredo Pesoli (@__rev) via Bynario Atlas (bynar.io)

Security

Available for: macOS Tahoe

Impact: An attacker in a privileged network position may be able to intercept network traffic

Description: A certificate validation issue was addressed with improved certificate validation.

CVE-2026-86889: Jaeho Nam, Jungbum Lee, Sangwi Kang, Hyeonguk Ko and Taekyoung Kwon from SNU CSE MMLAB (mmlab.snu.ac.kr)

Security

Available for: macOS Tahoe

Impact: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages

Description: A certificate validation issue was addressed with improved certificate validation.

CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier, Filip Olszak

SMB

Available for: macOS Tahoe

Impact: Mounting a maliciously crafted SMB network share may lead to system termination

Description: A use-after-free issue was addressed with improved memory management.

CVE-2026-43719: Jakob Pammer, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research

SMB

Available for: macOS Tahoe

Impact: Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory

Description: An out-of-bounds access issue was addressed with improved bounds checking.

CVE-2026-84543: Peter Malone

SMB

Available for: macOS Tahoe

Impact: A local user may be able to read kernel memory

Description: A race condition was addressed with improved locking.

CVE-2026-43690: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research

SMB

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-65376: 재영 정, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research

SMB

Available for: macOS Tahoe

Impact: Connecting to a malicious SMB server may lead to unexpected system termination

Description: An integer underflow was addressed with improved input validation.

CVE-2026-84536: 재영 정, Peter Malone, Feng Xue and XGPT of ThreatBook

SMB

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination or corrupt kernel memory

Description: The issue was addressed with improved memory handling.

CVE-2026-84537: Peter Malone, Feng Xue and XGPT of ThreatBook

SMB

Available for: macOS Tahoe

Impact: Connecting to a malicious SMB share may disclose kernel memory

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-65365: Jay Patel, Peter Malone

SMB

Available for: macOS Tahoe

Impact: Connecting to a malicious SMB server may lead to kernel memory corruption

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84515: 재영 정, Peter Malone

SMB

Available for: macOS Tahoe

Impact: Connecting to a malicious SMB server may lead to unexpected system termination

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-84509: Dave G.

smbx

Available for: macOS Tahoe

Impact: A remote attacker may be able to cause a denial-of-service

Description: A resource exhaustion issue was addressed with improved input validation.

CVE-2026-84553: Stuart Thomas

Software Update

Available for: macOS Tahoe

Impact: An app may be able to modify protected system files

Description: A permissions issue was addressed with improved path validation.

CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team

SoftwareUpdate

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with improved checks.

CVE-2026-65361: Rodolphe BRUNETTI (@eisw0lf) of Lupus Nova

Spotlight

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved state management.

CVE-2026-65378: Sindre Sorhus, Abodi Dawoud, 糖豆爸爸(@晴天组织), Robert Mindo, Niels Hofmans

Spotlight

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved access control.

CVE-2026-84621: Abodi Dawoud, Ujjwal Reddy Kalvolu Sreenivasa Reddy, Johan Wahyudi, Armend Gashi

Storage

Available for: macOS Tahoe

Impact: An app may be able to access user-sensitive data

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-65345: 이재영, Seung Je Seong, Jakob Pammer, Ilya Andr (andrd3v) of Positive Technologies

Storage

Available for: macOS Tahoe

Impact: An app may be able to modify protected parts of the file system

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-65348: Jérôme Djouder

StorageKit

Available for: macOS Tahoe

Impact: An app may be able to read arbitrary files

Description: A validation issue was addressed with improved input sanitization.

CVE-2026-43791: Amy (amys.website), Meridian Miftari, Aaron Grattafiori - NVIDIA AI Red Team

Symptom Framework

Available for: macOS Tahoe

Impact: A malicious application may be able to determine a user's current location

Description: A privacy issue was addressed with improved private data redaction for log entries.

CVE-2026-84513: Sindre Sorhus

TCC

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: A logging issue was addressed with improved data redaction.

CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom

udf

Available for: macOS Tahoe

Impact: An app may be able to cause unexpected system termination or read kernel memory

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-84572: Tomi (tk0) Koski (@tomikoski), Hari Shanmugam (The Hxr1)

udf

Available for: macOS Tahoe

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: A use after free issue was addressed with improved memory management.

CVE-2026-84506: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

WebDAV

Available for: macOS Tahoe

Impact: Connecting to a malicious WebDAV server may lead to unexpected app termination

Description: An out-of-bounds write issue was addressed by removing the vulnerable code.

CVE-2026-43677: bubu, Surya Narayan Kushwaha, Roman Zabicki, Richard Zana, Omar Cerrito, HE WEI(ギカク), Chris Bailey - Short Circuit, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research, Aswin Kumar Gokulakannan

WebDAV

Available for: macOS Tahoe

Impact: Connecting to a malicious WebDAV server may result in code execution

Description: A memory corruption issue was addressed with improved validation.

CVE-2026-65374: He Wei(ギカク), Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research

XPC

Available for: macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved state management.

CVE-2026-84617: Stuart Wallace

Additional recognition

AVEVideoEncoder

We would like to acknowledge tamdao for their assistance.

Bluetooth

We would like to acknowledge Suresh Sundaram for their assistance.

Calendar

We would like to acknowledge Dany Assuid, Jacob Hazak from Zero-Defense Labs, Varik Matevosyan, stratan (@5tratan) for their assistance.

dcerpc

We would like to acknowledge Surya Narayan Kushwaha for their assistance.

Kernel

We would like to acknowledge Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Nebula Security (@nebusecurity) for their assistance.

quarantine

We would like to acknowledge an anonymous researcher for their assistance.

Quick Look

We would like to acknowledge Peter Malone for their assistance.

rapportd

We would like to acknowledge Tae Woo Kim for their assistance.

Shortcuts

We would like to acknowledge Owen Pawling (@owenpawling) for their assistance.

Virtualization

We would like to acknowledge Ye Zhang (@VAR10CK) of Baidu Security for their assistance.

WindowServer

We would like to acknowledge Jex Amro for their assistance.

xar

We would like to acknowledge Matthew Dean for their assistance.

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

Published Date: