Apple Patches 25 macOS Vulnerabilities in Single July 2026 Disclosure
Apple released a critical security update on July 27, 2026, patching 25 vulnerabilities across macOS Sequoia, Sonoma, and Tahoe.

Key findings
- Apple patched 25 vulnerabilities in macOS Sequoia, Sonoma, and Tahoe on July 27, 2026.
- Flaws include memory corruption, sandbox escapes, and unauthorized data access risks.
- Patches are available in macOS Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6.
- No active exploitation was reported by Apple at the time of disclosure.
- Multiple CVEs address potential system termination or kernel memory corruption.
On July 27, 2026, Apple released a significant security update addressing 25 vulnerabilities across its macOS operating systems, including macOS Sequoia, macOS Sonoma, and macOS Tahoe. The batch of fixes, all disclosed on the same day, target a range of issues from memory corruption and sandbox escapes to unauthorized data access and system termination risks. These vulnerabilities, if exploited, could lead to unexpected system termination, kernel memory corruption, or unauthorized access to sensitive user data.
Several vulnerabilities fall into common categories:
- Memory Corruption and Unexpected Termination: A significant number of CVEs, including CVE-2026-43757, CVE-2026-43805, CVE-2026-39873, CVE-2026-43809, CVE-2026-43799, CVE-2026-43776, CVE-2026-43812, CVE-2026-64700, CVE-2026-43767, and CVE-2026-64697, were addressed by improved memory handling, bounds checking, or state management. These could lead to unexpected system termination or kernel memory corruption. CVE-2026-43776, a buffer overflow, specifically mentions the potential for arbitrary code execution.
- Sandbox Escape and Authorization Issues: Vulnerabilities such as CVE-2026-64737, CVE-2026-64740, CVE-2026-64721, CVE-2026-28900, CVE-2026-43672, CVE-2026-28849, CVE-2026-64707, and CVE-2026-64711 relate to authorization flaws or issues that could allow a malicious app to break out of its sandbox, bypass privacy preferences, or access files it should not. CVE-2026-28900 and CVE-2026-28849 specifically mention a file quarantine bypass via maliciously crafted ZIP archives, potentially bypassing Gatekeeper checks.
- Sensitive Data Access and Information Leakage: CVE-2026-43782, CVE-2026-64737, CVE-2026-64711, and CVE-2026-43756 address issues where an app might access sensitive user data or leak user information due to improved checks or state management.
- Denial of Service and Other Issues: CVE-2026-43777, a remote attacker could cause a denial of service. CVE-2026-43665 allows a local attacker to determine the legacy VNC password for Screen Sharing. CVE-2026-64716 involves processing a maliciously crafted image that may corrupt process memory. CVE-2026-43673 involves processing a maliciously crafted audio file that may corrupt process memory.
Apple addressed these vulnerabilities with improved bounds checking, state management, memory handling, entitlement checks, input validation, and other security enhancements. The fixes are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Other affected Apple operating systems also received patches, including iOS 26.6, iPadOS 26.6, watchOS 26.6, tvOS 26.6, and visionOS 26.6, depending on the specific CVE.
While Apple did not label any of these vulnerabilities as being actively exploited in the wild at the time of disclosure, the sheer number and variety of flaws underscore the importance of keeping macOS systems updated. Users should install the latest security updates to protect against potential attacks that could lead to system instability, data breaches, or unauthorized access. The coordinated disclosure of these 25 CVEs on a single day highlights a significant security patching event for Apple users.
The SANS Internet Storm Center noted that Apple patched a total of 187 vulnerabilities across its operating systems in July 2026, with many covering multiple platforms. SANS Internet Storm Center
The fixes are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Vypr Intelligence Malwarebytes Labs Cyber Security News The Hacker News