macOS Apple macOS Macintosh Operating System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Apple macOS.

Recent Apple macOS Security Advisories

Advisory Title Published
128072 macOS Sonoma 14.8.8 - Apple Security Content July 27, 2026
128071 macOS Sequoia 15.7.8 - Apple Security Content July 27, 2026
128067 macOS Tahoe 26.6 - Apple Security Content July 27, 2026
127595 macOS Tahoe 26.5.2 - Apple Security Content June 29, 2026
127115 macOS Tahoe 26.5 - Apple Security Content May 11, 2026
127117 macOS Sonoma 14.8.7 - Apple Security Content May 11, 2026
127116 macOS Sequoia 15.7.7 - Apple Security Content May 11, 2026
126795 macOS Sequoia 15.7.5 - Apple Security Content March 24, 2026
126796 macOS Sonoma 14.8.5 - Apple Security Content March 24, 2026
126794 macOS Tahoe 26.4 - Apple Security Content March 24, 2026

Known Exploited Apple macOS Vulnerabilities

The following Apple macOS vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Apple macOS Use-After-Free Vulnerability Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation.
CVE-2019-8526 Exploit Probability: 0.7%
April 17, 2023
Apple macOS Out-of-Bounds Write Vulnerability macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
CVE-2022-22675 Exploit Probability: 12.6%
April 4, 2022
Apple macOS Out-of-Bounds Read Vulnerability macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
CVE-2022-22674 Exploit Probability: 1.1%
April 4, 2022
Apple macOS Input Validation Error A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited.
CVE-2021-30713 Exploit Probability: 6.6%
November 3, 2021
Apple macOS Policy Subsystem Gatekeeper Bypass A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited.
CVE-2021-30657 Exploit Probability: 68.5%
November 3, 2021

The vulnerability CVE-2021-30657: Apple macOS Policy Subsystem Gatekeeper Bypass is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2022-22675: Apple macOS Out-of-Bounds Write Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.

Apple macOS EOL Dates

Ensure that you are using a supported version of Apple macOS. Here are some end of life, and end of support dates for Apple macOS.

Release EOL Date Status
26 -
Active

15 -
Active

14 -
Active

13 September 15, 2025
EOL

Apple macOS 13 became EOL in 2025.

12 September 16, 2024
EOL

Apple macOS 12 became EOL in 2024.

11 February 2, 2026
EOL

Apple macOS 11 became EOL in 2026.

10.15 February 2, 2026
EOL

Apple macOS 10.15 became EOL in 2026.

10.14 October 25, 2021
EOL

Apple macOS 10.14 became EOL in 2021.

10.13 December 1, 2020
EOL

Apple macOS 10.13 became EOL in 2020.

10.12 October 1, 2019
EOL

Apple macOS 10.12 became EOL in 2019.

10.11 December 1, 2018
EOL

Apple macOS 10.11 became EOL in 2018.

10.9 December 1, 2016
EOL

Apple macOS 10.9 became EOL in 2016.

10.8 August 13, 2015
EOL

Apple macOS 10.8 became EOL in 2015.

10.7 October 4, 2012
EOL

Apple macOS 10.7 became EOL in 2012.

10.6 July 25, 2011
EOL

Apple macOS 10.6 became EOL in 2011.

10.5 August 13, 2009
EOL

Apple macOS 10.5 became EOL in 2009.

10.4 November 14, 2007
EOL

Apple macOS 10.4 became EOL in 2007.

10.3 April 15, 2005
EOL

Apple macOS 10.3 became EOL in 2005.

10.2 October 3, 2003
EOL

Apple macOS 10.2 became EOL in 2003.

10.1 June 6, 2002
EOL

Apple macOS 10.1 became EOL in 2002.

By the Year

In 2026 there have been 473 vulnerabilities in Apple macOS with an average score of 6.9 out of ten. Last year, in 2025 macOS had 679 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in macOS in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.29.




Year Vulnerabilities Average Score
2026 473 6.91
2025 679 6.62
2024 543 6.42
2023 426 6.73
2022 381 7.10
2021 500 7.01
2020 342 7.24
2019 305 7.62
2018 89 7.25

It may take a day or so for new macOS vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apple macOS Security Vulnerabilities

Out-of-Bounds Read in macOS (Sequoia/Sonoma/Tahoe) Up To 15.7.8/14.8.8/26.6
CVE-2026-43757 9.8 - Critical - July 27, 2026

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Out-of-bounds Read

macOS Authorization & Sandbox Break Fix (Sequoia, Sonoma)
CVE-2026-64737 8.2 - High - July 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

Authorization

macOS App Data Access Vulnerability (Fixed in Sequoia 15.7.8)
CVE-2026-43782 5.5 - Medium - July 27, 2026

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

Information Disclosure

Apple OS Race Condition Enables Kernel Write fixed in iOS 26.6, macOS 15.7.8
CVE-2026-43805 9.8 - Critical - July 27, 2026

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

Race Condition

Memory Handling Leak in macOS SMB Client Causes System Termination (Pre15.7/14.8/26.6)
CVE-2026-39873 9.8 - Critical - July 27, 2026

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination.

Buffer Overflow

macOS kernel memory disclosure via bounds check flaw (before Sequoia 15.7.8)
CVE-2026-64776 5.5 - Medium - July 27, 2026

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.

Out-of-bounds Read

iOS/macOS Code Signing Bypass (CVE-2026-43813) Fixed in 26.6
CVE-2026-43813 7.1 - High - July 27, 2026

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.

Improper Input Validation

Apple OS State Management Data Leak (CVE-2026-64721) - fixed in 26.6
CVE-2026-64721 5.5 - Medium - July 27, 2026

This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

Improper Control of a Resource Through its Lifetime

macOS Info Disclosure Vulnerability Fixed in Sequoia 15.7.8 & Sonoma 14.8.8
CVE-2026-20672 5.5 - Medium - July 27, 2026

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.

Information Disclosure

Apple OS Sandbox Escape via Path Validation (iOS 26.6, macOS Sequoia 15.7.8)
CVE-2026-64740 9.3 - Critical - July 27, 2026

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.

Directory traversal

Buffer overflow in macOS Tahoe before 26.6
CVE-2026-64691 9.8 - Critical - July 27, 2026

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Classic Buffer Overflow

Apple OS Audio Framework Memory Corruption via Malicious Audio File (iOS 26.6+)
CVE-2026-43673 7.8 - High - July 27, 2026

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.

Buffer Overflow

SAFARI USE-AFTER-FREE CRASH VULN FIXED IN 26.6
CVE-2026-64783 8.8 - High - July 27, 2026

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Dangling pointer

macOS Sequoia 15.7.8 OOB Read CVE-2026-43809
CVE-2026-43809 9.8 - Critical - July 27, 2026

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Out-of-bounds Read

Apple macOS ScreenSharing VNC Password Disclosure Before 15.7.8/14.8.8
CVE-2026-43665 5.5 - Medium - July 27, 2026

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.

AuthZ

Remote DoS via Improper Input Validation in macOS 15.7.8/14.8.8/26.6
CVE-2026-43777 7.5 - High - July 27, 2026

This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause a denial of service.

Improper Input Validation

Apple OS Use-After-Free before 26.6 (iOS & macOS)
CVE-2026-43799 9.8 - Critical - July 27, 2026

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Dangling pointer

Apple OS Buffer Overflow Fixed in iOS 26.6 / macOS 15.7.8
CVE-2026-43776 7.8 - High - July 27, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Classic Buffer Overflow

macOS Gatekeeper ZIP Quarantine Bypass (fixed 15.7.8/14.8.8)
CVE-2026-28900 5.5 - Medium - July 27, 2026

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

Authentication Bypass by Spoofing

Auth bypass via state mgmt in macOS 15.7.8, 14.8.8, 26.6
CVE-2026-43672 7.1 - High - July 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.

AuthZ

macOS App Access Issue with Sensitive Data fixed in 14.8.8/26.6
CVE-2026-43760 5.5 - Medium - July 27, 2026

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.

Authorization

Apple OS ImageProcessor Memory Corruption (CVE-2026-64716) before 26.6
CVE-2026-64716 7.8 - High - July 27, 2026

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may corrupt process memory.

Buffer Overflow

macOS Kernel Race Condition Causing Termination (Fixed 15.7.8/14.8.8/26.6)
CVE-2026-28982 9.8 - Critical - July 27, 2026

A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

Race Condition

Safari Memory Corruption Fixed in 26.6 (iOS, macOS, watchOS, visionOS)
CVE-2026-64757 8.8 - High - July 27, 2026

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Buffer Overflow

Apple OSes UAF Fix in 26.6
CVE-2026-64700 9.8 - Critical - July 27, 2026

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Dangling pointer

Race Condition in Apple OS 26.6 Can Cause System Crash
CVE-2026-64720 9.8 - Critical - July 27, 2026

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Race Condition

macOS Gatekeeper ZIP Bypass (before 15.7.8 & 14.8.8)
CVE-2026-28849 5.5 - Medium - July 27, 2026

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

Authentication Bypass by Spoofing

Apple OS Use-After-Free (iOS 26.6, macOS 15.7.8)
CVE-2026-43812 9.8 - Critical - July 27, 2026

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.

Dangling pointer

Safari DoS via State Mgmt in 26.5+
CVE-2026-43804 6.5 - Medium - July 27, 2026

This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.

Resource Exhaustion

macOS logic flaw enabling app data access (fixed in 15.7.8, 14.8.8, 26.6)
CVE-2026-43756 5.5 - Medium - July 27, 2026

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.

AuthZ

Apple iOS/macOS: Permission Bypass allows delete of unauthorized files (fixed before 26.6)
CVE-2026-64707 5.5 - Medium - July 27, 2026

A permissions issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to delete files for which it does not have permission.

Incorrect Permission Assignment for Critical Resource

Info Leak via Entitlement Bypass in macOS Sequoia 15.7.8
CVE-2026-64711 5.5 - Medium - July 27, 2026

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.

AuthZ

iOS 26.6 Authorization flaw allows contact addition without permission
CVE-2026-64746 9.8 - Critical - July 27, 2026

An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.

AuthZ

macOS bug may cause app crash in Sequoia 15.7.8/Sonoma 14.8.8/Tahoe 26.6
CVE-2026-43767 5 - Medium - July 27, 2026

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Buffer Overflow

macOS Kernel Mem Corrupt via App (Sequoia 15.7.8 / Sonoma 14.8.8 / Tahoe 26.6)
CVE-2026-64697 9.8 - Critical - July 27, 2026

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

Buffer Overflow

macOS Memory Corruption via App (pre-14.8.8)
CVE-2026-28911 9.8 - Critical - July 27, 2026

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.

Buffer Overflow

Apple iOS/macOS Permission Fault Enabling Fingerprinting, fixed 26.6
CVE-2026-43730 9.8 - Critical - July 27, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.

Information Disclosure

macOS Sandbox Bypass in macOS Tahoe 26.6 Allows App Data Access
CVE-2026-43819 5.5 - Medium - July 27, 2026

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive user data.

Authorization

macOS Stack Overflow (DoS) Fixed in Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6
CVE-2026-43771 7.1 - High - July 27, 2026

A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.

Stack Overflow

macOS file parser OOB read fixed in 15.7.8,14.8.8,26.6
CVE-2026-43747 7.1 - High - July 27, 2026

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.

Out-of-bounds Read

Apple OS NFS Client Buffer Overflow Kernel Mem Corruption, Fixed 26.6
CVE-2026-28931 8.8 - High - July 27, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.

Classic Buffer Overflow

macOS Kernel Memory Corruption Fixed in Sequoia 15.7.8, Sonoma 14.8.8
CVE-2026-43710 9.8 - Critical - July 27, 2026

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker may be able to cause unexpected system termination or corrupt kernel memory.

Buffer Overflow

macOS Path Handling Issue Allows Sandbox Escape (Fixed in 15.7.8/26.6)
CVE-2026-64731 9.8 - Critical - July 27, 2026

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

Directory traversal

Apple OS integer overflow: vulnerable pre-26.6 on iOS, iPadOS, macOS, tvOS
CVE-2026-64766 7.8 - High - July 27, 2026

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Integer Overflow or Wraparound

Apple iOS/macOS 26.6: OOB Write Fixed Remote Attacker Termination Risk
CVE-2026-43803 9.8 - Critical - July 27, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to cause unexpected system termination.

Memory Corruption

macOS Privilege Escalation via Permission Issue (fixed 15.7.8,14.8.8,26.6)
CVE-2026-39875 7.8 - High - July 27, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

Incorrect Default Permissions

Apple OS OOB Write (CVE-2026-64770): Fixed in iOS 26.6
CVE-2026-64770 9.8 - Critical - July 27, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

Memory Corruption

macOS & tvOS Pre-26.6 Type Confusion App-Induced System Crash
CVE-2026-64727 9.8 - Critical - July 27, 2026

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination.

Object Type Confusion

Safari Authorization Flaw Pre-26.6 Allows App Access to Sensitive Data
CVE-2026-43792 6.5 - Medium - July 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.

AuthZ

macOS Sequoia 15.7.8 ENV Variable Validation Failure Leads to System Termination
CVE-2026-43793 9.8 - Critical - July 27, 2026

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Improper Input Validation

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apple macOS or by Apple? Click the Watch button to subscribe.

Apple
Vendor

Apple macOS
Macintosh Operating System

subscribe