Apple Releases 25 macOS Security Patches, Including CUPS Privilege Escalation Flaw
Apple patched 25 vulnerabilities in macOS Sonoma, Sequoia, and Tahoe on July 27, 2026, addressing risks from memory corruption to sandbox escapes.

Key findings
- Apple patched 25 vulnerabilities in macOS Sonoma, Sequoia, and Tahoe on July 27, 2026.
- Flaws include memory corruption, sandbox escapes, unauthorized data access, and system termination risks.
- CVE-2026-39875, a CUPS vulnerability, allows local privilege escalation, with a public PoC released.
- Patches are available in macOS Sonoma 14.8.8, Sequoia 15.7.8, and Tahoe 26.6.
- No active exploitation was reported by Apple at the time of disclosure.
On July 27, 2026, Apple released a significant security update addressing 25 vulnerabilities across its macOS operating systems, including macOS Sonoma. The batch of fixes, all disclosed on the same day, target a range of issues from memory corruption and sandbox escapes to unauthorized data access and system termination. These vulnerabilities, if exploited, could lead to unexpected system termination, kernel memory corruption, or sandbox escapes. Apple patched these issues in macOS Sonoma 14.8.8, macOS Sequoia 15.7.8, and macOS Tahoe 26.6.
Several vulnerabilities focus on memory management and data access. CVE-2026-43757, CVE-2026-43809, and CVE-2026-43747 involve out-of-bounds reads, potentially leading to unexpected system termination or app crashes. CVE-2026-39873, CVE-2026-64716, CVE-2026-43767, CVE-2026-64697, CVE-2026-28911, and CVE-2026-43710 all relate to improved memory handling, with potential impacts ranging from system termination to corrupting kernel memory or system processes. CVE-2026-43756 and CVE-2026-43760, described as logic and access issues respectively, could allow an app to access sensitive user data. CVE-2026-43771, a stack overflow, could lead to a denial-of-service.
Security concerns around sandbox escapes and authorization bypasses are also prominent. CVE-2026-64737 and CVE-2026-43672 address authorization issues, potentially allowing a malicious app to break out of its sandbox or bypass privacy preferences. CVE-2026-28900 and CVE-2026-28849, related to file quarantine, could allow a maliciously crafted ZIP archive to bypass Gatekeeper checks. CVE-2026-64766, an integer overflow, could lead to unexpected app termination or arbitrary code execution when processing a malicious file. CVE-2026-28982, a race condition, could allow a remote user to cause system termination or corrupt kernel memory.
One vulnerability, CVE-2026-39875, specifically impacts the Common UNIX Printing System (CUPS) and allows a local attacker to gain root privileges through arbitrary file writes. A public proof-of-concept for this vulnerability was released shortly after the disclosure, highlighting its potential for privilege escalation. Cyber Security News
Another notable vulnerability, CVE-2026-43665, could allow a local attacker to determine the legacy VNC password for Screen Sharing. CVE-2026-43777, a parsing issue, could be exploited by a remote attacker to cause a denial-of-service.
Apple addressed these 25 vulnerabilities with improved bounds checking, state management, input validation, memory handling, entitlement checks, access restrictions, and path validation across various components. The fixes are included in macOS Sonoma 14.8.8, macOS Sequoia 15.7.8, and macOS Tahoe 26.6. While Apple did not report active exploitation at the time of disclosure, the nature of some flaws, such as the CUPS vulnerability with a public PoC, warrants prompt attention from users. Users are advised to update their macOS systems to the latest available versions to mitigate these risks. Vypr Intelligence SANS Internet Storm Center