Apple macOS: 25 Vulnerabilities Patched in Same-Day Security Update
Apple patched 25 macOS vulnerabilities on September 14, 2026, addressing memory corruption, permissions, and network security flaws.

Key findings
- Apple patched 25 macOS vulnerabilities disclosed on September 14, 2026.
- Vulnerabilities include permissions issues, memory corruption, and certificate validation flaws.
- Fixes are available in macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7.
- No vulnerabilities were reported as actively exploited in the wild.
- The batch includes issues related to accessing restricted files, sensitive data, and potential privilege escalation.
On September 14, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities in macOS, alongside updates for iOS, iPadOS, watchOS, tvOS, and visionOS. The disclosures, all published on the same day, highlight a range of issues including memory corruption, privacy concerns, and potential data access vulnerabilities. These vulnerabilities were fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Several vulnerabilities fall into common categories:
Permissions and Access Control Issues
A significant portion of the disclosed vulnerabilities relate to improper permissions and authorization. For instance, CVE-2026-86917 and CVE-2026-86910 describe issues where an application could gain root privileges or access restricted files due to inadequate path validation and additional restrictions. Similarly, CVE-2026-86891 and CVE-2026-86417 allowed apps to access Bluetooth device information and sensitive user data, respectively, due to authorization flaws. CVE-2026-84618 and CVE-2026-84587 also fall into this category, enabling access to sensitive user data and protected user data through permission issues. Furthermore, CVE-2026-84612 could allow an app to read persistent device identifiers.
Memory Corruption and Handling Flaws
Multiple vulnerabilities stem from memory corruption issues, including out-of-bounds writes and heap buffer overflows. CVE-2026-86924 describes a memory corruption issue addressed with improved input validation. CVE-2026-86882 and CVE-2026-84611 involve out-of-bounds writes that could lead to unexpected process termination or memory corruption when processing maliciously crafted images or 3D models. CVE-2026-86876, another out-of-bounds write, could allow a sandboxed process to circumvent sandbox restrictions. CVE-2026-84622 points to a memory initialization issue where an app with root privileges could read uninitialized kernel memory. CVE-2026-84616 and CVE-2026-84602 are type confusion issues that could lead to unexpected system termination. CVE-2026-84630 and CVE-2026-84607 involve race conditions that could lead to unexpected system termination or arbitrary code execution with kernel privileges, respectively. CVE-2026-84632 also relates to memory handling, potentially causing memory corruption when processing 3D models. CVE-2026-86870 is a heap buffer overflow leading to unexpected app termination.
Network and Certificate Validation Issues
CVE-2026-86889 and CVE-2026-86881 address certificate validation issues. The former could allow an attacker in a privileged network position to intercept network traffic, while the latter could be exploited by an attacker with a compromised intermediate certificate authority.
Information Disclosure
CVE-2026-84626 is an information disclosure issue that could allow an app to identify what other apps a user has installed. CVE-2026-86897, fixed with entitlement checks, could allow an app to access sensitive user data. CVE-2026-86902 involves a parsing issue in directory path handling that could allow an app to access sensitive user data.
Exploitation and Response
According to related news coverage, none of these vulnerabilities were reported as actively exploited in the wild. Apple has addressed these issues with various improvements, including enhanced input validation, additional restrictions, improved path validation, additional entitlement checks, improved state management, improved bounds checking, and improved memory handling. The fixes are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
This batch of vulnerabilities underscores the importance of timely patching for Apple's operating systems. Users are advised to update to the latest available versions to protect against potential security risks, including unauthorized data access, privilege escalation, and system instability. The consistent patching across multiple operating systems indicates Apple's ongoing commitment to security, but also highlights the persistent nature of complex vulnerabilities in large software ecosystems. ,cve_ids:[CVE-2026-86924,CVE-2026-86917,CVE-2026-86910,CVE-2026-86902,CVE-2026-86897,CVE-2026-86891,CVE-2026-86889,CVE-2026-86882,CVE-2026-86881,CVE-2026-86876,CVE-2026-86870,CVE-2026-84632,CVE-2026-84630,CVE-2026-84626,CVE-2026-84624,CVE-2026-84622,CVE-2026-84620,CVE-2026-84618,CVE-2026-84617,CVE-2026-84616,CVE-2026-84612,CVE-2026-84611,CVE-2026-84607,CVE-2026-84602,CVE-2026-84587],image_prompt: