VYPR
Vypr IntelligenceAI-generatedJul 27, 2026· 25 CVEs

macOS Tahoe: 25 Security Flaws Patched in Single July 2026 Disclosure

Apple patched 25 diverse security vulnerabilities in macOS Tahoe on July 27, 2026, ranging from memory corruption to sandbox escape flaws.

Key findings

  • Apple patched 25 vulnerabilities in macOS Tahoe on July 27, 2026, affecting core system components.
  • Vulnerabilities include memory corruption, sandbox escapes, and unauthorized data access risks.
  • Fixes are available in macOS Tahoe 26.6 and other Apple operating system updates.
  • No active exploitation of these CVEs was reported by Apple at the time of disclosure.

On July 27, 2026, Apple released a significant security update addressing 25 vulnerabilities across its macOS operating systems, including macOS Tahoe. The batch of fixes, all disclosed on the same day, target a range of issues from out-of-bounds reads and buffer overflows to authorization bypasses and race conditions. These vulnerabilities, if exploited, could lead to unexpected system termination, kernel memory corruption, sandbox escapes, or unauthorized access to sensitive user data.

Several vulnerabilities focus on memory management and handling. CVE-2026-43757 and CVE-2026-43809 involve out-of-bounds reads that could cause unexpected system termination, fixed with improved bounds checking. CVE-2026-39873 and CVE-2026-64716 address memory handling issues, with the former potentially leading to system termination when connecting to a malicious SMB server, and the latter corrupting process memory when processing a crafted image. CVE-2026-64691 and CVE-2026-64697 describe buffer overflows and memory handling issues, respectively, that could lead to system termination or kernel memory corruption. CVE-2026-43812 and CVE-2026-64697 detail use-after-free vulnerabilities, which could also result in system termination.

Authorization and access control were also key themes in this disclosure. CVE-2026-64737 and CVE-2026-64740, for instance, are authorization issues that could allow a malicious app to break out of its sandbox, fixed with improved state management and path validation. CVE-2026-43672 and CVE-2026-43760 address authorization and access issues, respectively, potentially allowing malicious applications to bypass privacy preferences or access sensitive user data. CVE-2026-64746, an authorization issue, could permit an app to add contacts without user consent, while CVE-2026-43730, a permissions issue, could enable user fingerprinting.

Other vulnerabilities include race conditions, such as CVE-2026-43805 and CVE-2026-64720, which could lead to system termination or kernel memory writes. CVE-2026-28982 also involves a race condition that could result in system termination or kernel memory corruption. CVE-2026-43777 describes a remote denial-of-service vulnerability, fixed with improved input validation. CVE-2026-43776, a buffer overflow, could lead to app termination or arbitrary code execution when processing a crafted file. CVE-2026-43813, a validation issue, could allow a malicious app to bypass code signing enforcement. Finally, CVE-2026-43804, addressed with improved state management, could lead to an app denial-of-service when visiting a malicious website.

The fixes for these vulnerabilities are included in macOS Tahoe 26.6, alongside updates for macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8. Other affected operating systems and applications, such as iOS, iPadOS, tvOS, watchOS, and Safari, also received corresponding patches. Apple has not indicated any of these vulnerabilities were exploited in the wild.

Users of macOS Tahoe and other affected Apple products are strongly advised to update to the latest versions to mitigate these security risks. The broad range of vulnerabilities patched underscores the importance of timely security updates for maintaining the integrity and security of Apple's ecosystem.

The vulnerabilities patched include: CVE-2026-43757, CVE-2026-64737, CVE-2026-43782, CVE-2026-43805, CVE-2026-39873, CVE-2026-43813, CVE-2026-64740, CVE-2026-64691, CVE-2026-64783, CVE-2026-43809, CVE-2026-43777, CVE-2026-43776, CVE-2026-43672, CVE-2026-43760, CVE-2026-64716, CVE-2026-28982, CVE-2026-64720, CVE-2026-43812, CVE-2026-43804, CVE-2026-43756, CVE-2026-64711, CVE-2026-64746, CVE-2026-43767, CVE-2026-64697, CVE-2026-43730.

AI-written article. Grounded in 25 CVE records listed below.