VYPR
Vypr IntelligenceAI-generatedSep 14, 2026· 25 CVEs

macOS Tahoe: 25 Vulnerabilities Patched in Same-Day Apple Security Update

Apple patched 25 macOS Tahoe vulnerabilities on September 14, 2026, addressing issues from data access to system termination, with fixes in version 26.7.

Key findings

  • Apple patched 25 macOS Tahoe vulnerabilities disclosed on September 14, 2026.
  • Vulnerabilities include permissions issues, memory corruption, sandbox escapes, and denial-of-service flaws.
  • Fixes are available in macOS Tahoe 26.7 and other Apple operating system updates.
  • No vulnerabilities were reported as actively exploited in the wild.
  • High severity flaws include path traversal and out-of-bounds writes with CVSS scores up to 8.8.

On September 14, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities in macOS Tahoe, alongside updates for other Apple operating systems. The disclosures, all published on the same day, highlight a range of issues including memory corruption, privacy concerns, and potential data access vulnerabilities. These vulnerabilities, patched in macOS Tahoe 26.7, represent a broad spectrum of security weaknesses, with potential impacts ranging from unauthorized data access to system termination and arbitrary code execution. Notably, none of the vulnerabilities were reported as actively exploited in the wild, according to Vypr Intelligence N3, N7.

The disclosed vulnerabilities can be broadly categorized by their impact and the underlying technical flaws. Several issues relate to permissions and path validation, allowing apps to potentially access sensitive user data or modify protected system files. For instance, CVE-2026-84618 and CVE-2026-84609, both addressed with improved validation, highlight these risks.

Memory corruption vulnerabilities were also prominent in this batch. CVE-2026-65391 and CVE-2026-65390, both rated High with a CVSSv3 score of 8.8, involve out-of-bounds writes and integer overflows, respectively, when processing maliciously crafted web content, potentially leading to memory corruption. Similarly, CVE-2026-84568, a High severity path traversal issue, could allow an attacker to execute arbitrary code with root privileges.

Several vulnerabilities were related to sandbox escapes and authorization flaws. CVE-2026-84580 and CVE-2026-84578, for example, were addressed with improved checks and logic, preventing apps from breaking out of their sandbox. CVE-2026-65378, an authorization issue, was fixed with improved state management, preventing unauthorized data access.

Denial-of-service (DoS) vulnerabilities were also present, such as CVE-2026-84553, a High severity resource exhaustion issue, and CVE-2026-84538, a Medium severity DoS issue, both addressed with improved input validation.

The fixes for these vulnerabilities are available in macOS Tahoe 26.7. Other affected operating systems and their respective patch versions include iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, tvOS 27, visionOS 27, and watchOS 27. Safari received updates with Safari 26.6.1 and Safari 26.7.1 for some of these issues.

This coordinated disclosure of 25 vulnerabilities underscores the ongoing efforts in identifying and mitigating security risks across Apple's ecosystem. While the sheer volume of patches, over 260 across all Apple products according to The Register N1, is notable, the absence of reported in-the-wild exploitation provides a window for users to update their systems without immediate external threat pressure. Users are advised to update to the latest available versions to protect against these potential security weaknesses. N2, N8

AI-written article. Grounded in 25 CVE records listed below.