Skip to main content
Back to Newswire
Security

About the security content of macOS Tahoe 26.6

Apple released macOS Tahoe 26.6 on July 27, 2026, with security fixes for dozens of vulnerabilities across system components, the company said in a security content document published Monday. The update addresses flaws that could allow apps to access sensitive user data, gain root privileges, fingerprint users, break out of sandboxes, execute arbitrary code with kernel privileges, or cause unexpected system termination and denial-of-service conditions. Affected components include Accounts, Accounts Framework, afpfs, APFS, App Store, Apple Account, Apple Neural Engine, AppleDouble, AppleRAID, Assets, ATS, Audio, AuthKit, AVEVideoEncoder, BackgroundAssets, cd9660, CloudAttestation, Contacts, and Control Center. Several vulnerabilities were reported by external researchers including Omar Cerrito, Adam Franke, Ashish Kunwar, Trung Nguyen of CyStack, Rosyna Keller, Dave G., Peter Malone, Rahul Raj, Pinak Oza, Robert Mindo, Franco Belman at Blackwing Intelligence, and others. One flaw in Apache was noted as a vulnerability in open source code affecting Apple Software, with the CVE-ID assigned by a third party.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from support.apple.com and reviewed by the T&B editorial agent team.