macOS Tahoe: 25 Vulnerabilities Patched in Same-Day Apple Security Update
Key findings • 25 vulnerabilities disclosed together for macOS Tahoe on September 14, 2026. • Flaws include permissions issues, out-of-bounds writes/reads, and authorization problems. • P…

Key findings
- 25 vulnerabilities disclosed together for macOS Tahoe on September 14, 2026.
- Flaws include permissions issues, out-of-bounds writes/reads, and authorization problems.
- Potential impacts range from data access to system termination and arbitrary code execution.
- All issues fixed in macOS Tahoe 26.7; no active exploitation reported.
- Covers privacy risks, system stability, and denial-of-service vulnerabilities.
On September 14, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities in macOS Tahoe, alongside updates for other Apple operating systems. The disclosures, all published on the same day, highlight a range of issues including memory corruption, privacy concerns, and potential data access vulnerabilities. These vulnerabilities, fixed in macOS Tahoe 26.7, underscore the importance of timely patching for maintaining system security and user data integrity.
Several vulnerabilities stem from issues with memory handling and bounds checking, leading to potential system termination or kernel memory corruption. CVE-2026-84581, an out-of-bounds write, and CVE-2026-84566, related to memory handling, could allow local attackers to cause system instability. Similarly, CVE-2026-84619 and CVE-2026-84519, both out-of-bounds write issues, could lead to unexpected system termination or kernel memory corruption when processing maliciously crafted disk images or files. CVE-2026-84575 also involves an out-of-bounds write, potentially causing unexpected app termination. CVE-2026-84509, an out-of-bounds read, could result in system termination when connecting to a malicious SMB server.
Privacy and data access were also key concerns addressed in this batch. CVE-2026-86888, a permissions issue, could allow a local app to read persistent account identifiers. CVE-2026-84621, an authorization issue, might permit an app to access sensitive user data. This theme of unauthorized data access is echoed in CVE-2026-84576, CVE-2026-84573, and CVE-2026-84521, all of which could allow an app to access sensitive user data. CVE-2026-84562, a race condition, could allow an app to access protected user data. Furthermore, CVE-2026-84559, a permissions issue, could allow a malicious application to access restricted files.
Other vulnerabilities addressed include path traversal and handling issues. CVE-2026-84568, a path traversal vulnerability, could allow an attacker with control of a network directory server to execute arbitrary code with root privileges. CVE-2026-84534, a path handling issue, could allow an attacker to write arbitrary files after extracting a maliciously crafted archive.
Denial-of-service vulnerabilities were also present. CVE-2026-84553, a resource exhaustion issue, and CVE-2026-84538, a denial-of-service issue, could be exploited by remote attackers to disrupt system availability. Additionally, CVE-2026-84580 and CVE-2026-84578, both described as logic issues or improved checks, could allow an app to break out of its sandbox. CVE-2026-84552, related to memory handling, could cause unexpected system termination. CVE-2026-84511, an out-of-bounds write, could lead to unexpected process termination. Finally, CVE-2026-65401, a race condition, could cause unexpected system termination.
All 25 vulnerabilities were fixed in macOS Tahoe 26.7. Other affected Apple operating systems, including iOS, iPadOS, macOS Golden Gate, macOS Sequoia, tvOS, and watchOS, also received corresponding patches. According to related security advisories, none of these vulnerabilities were reported as actively exploited in the wild at the time of disclosure. Users are strongly advised to update to macOS Tahoe 26.7 or later to mitigate these security risks.
This coordinated disclosure of numerous vulnerabilities highlights a broad security sweep by Apple, addressing critical flaws across its ecosystem. While no active exploitation was reported, the range of potential impacts—from data access and privilege escalation to system stability—underscores the importance of applying these security updates promptly to protect against potential future threats.
CVE-2026-86888, CVE-2026-84621, CVE-2026-84619, CVE-2026-84609, CVE-2026-84581, CVE-2026-84580, CVE-2026-84578, CVE-2026-84576, CVE-2026-84575, CVE-2026-84573, CVE-2026-84568, CVE-2026-84566, CVE-2026-84562, CVE-2026-84559, CVE-2026-84553, CVE-2026-84552, CVE-2026-84548, CVE-2026-84538, CVE-2026-84534, CVE-2026-84527, CVE-2026-84525, CVE-2026-84519, CVE-2026-84511, CVE-2026-84509, CVE-2026-65401