VYPR
Vypr IntelligenceAI-generatedSep 14, 2026· 25 CVEs

macOS Sequoia: 25 Vulnerabilities Patched in Same-Day Apple Security Update

Apple patched 25 vulnerabilities in macOS Sequoia, including a critical flaw allowing modification of protected system files, on September 14, 2026.

Key findings

  • Apple patched 25 vulnerabilities in macOS Sequoia on September 14, 2026, including one critical flaw.
  • Vulnerabilities range from permissions issues and path traversal to memory corruption and denial-of-service flaws.
  • The critical CVE-2026-84609 allows an app to modify protected system files.
  • High-severity flaws include buffer overflows and out-of-bounds writes, potentially leading to kernel memory corruption.
  • Fixes are available in macOS Sequoia 15.8 and other Apple operating system updates.
  • No active exploitation of these vulnerabilities was reported in the wild.

On September 14, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities in macOS Sequoia, alongside updates for numerous other Apple operating systems. The disclosures, all published on the same day, highlight a range of issues including memory corruption, privacy concerns, and potential data access vulnerabilities. These vulnerabilities, patched in macOS Sequoia 15.8, represent a substantial security effort by Apple.

The disclosed vulnerabilities span several categories, including permissions issues, out-of-bounds writes and reads, path traversal, and denial-of-service flaws.

Several CVEs address permissions issues, where an app might gain unauthorized access to sensitive user data or modify protected system files. CVE-2026-84618, CVE-2026-84609, CVE-2026-84555, CVE-2026-65348, and CVE-2026-64701 fall into this category, with some allowing for potential privilege escalation to root.

Memory corruption vulnerabilities were also prevalent. CVE-2026-84512 and CVE-2026-43815 describe buffer overflows that could lead to kernel memory corruption or unexpected system termination. Similarly, CVE-2026-84575, CVE-2026-84511, and CVE-2026-64736 detail out-of-bounds write issues that could result in unexpected app termination or kernel memory corruption. CVE-2026-84565 involves an out-of-bounds read, and CVE-2026-43761 is another out-of-bounds write.

Other vulnerabilities include path traversal (CVE-2026-84568), which could allow an attacker to execute arbitrary code with root privileges, and resource exhaustion or denial-of-service issues (CVE-2026-84553, CVE-2026-84538). Integer overflow (CVE-2026-84548) and race conditions (CVE-2026-65358, CVE-2026-64717) were also addressed.

The batch includes a critical vulnerability, CVE-2026-84609, with a CVSSv3 score of 9.8, related to a permissions issue that could allow an app to modify protected system files. Several high-severity vulnerabilities, such as CVE-2026-84512 (CVSSv3 8.8) and CVE-2026-43815 (CVSSv3 8.8), involve buffer overflows with severe consequences.

According to related news coverage, none of the vulnerabilities were reported as actively exploited in the wild.

The fixes for these vulnerabilities are available in macOS Sequoia 15.8, macOS Golden Gate 27, and macOS Tahoe 26.7, among other operating system updates. Some specific CVEs also mention fixes in earlier branches like macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8.

This coordinated disclosure highlights the ongoing challenges in securing complex operating systems and the increasing effectiveness of vulnerability research, potentially driven by AI advancements as suggested by The Register. Users are advised to update their macOS systems to the latest available versions to mitigate these risks.

AI-written article. Grounded in 25 CVE records listed below.