Skip to main content
Security

About the security content of macOS Tahoe 26.6

Apple released macOS Tahoe 26.6 on July 27, 2026, with security fixes for dozens of vulnerabilities across system components, the company said in a security content document published Monday. The update addresses flaws that could allow apps to access sensitive user data, gain root privileges, fingerprint users, break out of sandboxes, execute arbitrary code with kernel privileges, or cause unexpected system termination and denial-of-service conditions. Affected components include Accounts, Accounts Framework, afpfs, APFS, App Store, Apple Account, Apple Neural Engine, AppleDouble, AppleRAID, Assets, ATS, Audio, AuthKit, AVEVideoEncoder, BackgroundAssets, cd9660, CloudAttestation, Contacts, and Control Center. Several vulnerabilities were reported by external researchers including Omar Cerrito, Adam Franke, Ashish Kunwar, Trung Nguyen of CyStack, Rosyna Keller, Dave G., Peter Malone, Rahul Raj, Pinak Oza, Robert Mindo, Franco Belman at Blackwing Intelligence, and others. One flaw in Apache was noted as a vulnerability in open source code affecting Apple Software, with the CVE-ID assigned by a third party.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from support.apple.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security
Security

Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...

Security Infrastructure
Security Infrastructure

GitLab patches maximum-severity file-read flaw as probes hit exposed servers

GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said. The vuln...

Products Security
Products Security

Figma launches Japan data residency for enterprise file hosting

Figma introduced data residency in Japan, letting enterprise customers store Figma Design, FigJam, Figma Slides, and Figma Make file data in the country. The company said the option responds to customer demand for domestic storag...