Full Disclosure mailing list archives
APPLE-SA-09-14-2026-4 macOS Tahoe 26.7
From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 14 Sep 2026 15:07:05 -0700
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-09-14-2026-4 macOS Tahoe 26.7 macOS Tahoe 26.7 addresses the following issues. Information about the security content is also available at https://support.apple.com/149042. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Accelerate Framework Available for: macOS Tahoe Impact: Processing a maliciously crafted image may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-86882: Peter Malone Accessibility Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved data protection. CVE-2026-43664: Stuart Wallace, Rosyna Keller of Totally Not Malicious Software, Jian Lee (@speedyfriend433), Ilya Andr (andrd3v), Gongyu Ma (@Mezone0), David Strnadel, Daniel Febrero, CJ Vana, Asaf Cohen APFS Available for: macOS Tahoe Impact: An application may be able to access restricted files Description: A permissions issue was addressed with improved path validation. CVE-2026-86910: an anonymous researcher APFS Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination or write kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84523: Cem Onat Karagun, an anonymous researcher App Store Available for: macOS Tahoe Impact: A local app may be able to read a persistent account identifier Description: A permissions issue was addressed with additional restrictions. CVE-2026-86888: Zhongcheng Li (CK01) AppKit Available for: macOS Tahoe Impact: An app may be able to access protected user data Description: A permissions issue was addressed with additional restrictions. CVE-2026-84587: an anonymous researcher Apple Account Available for: macOS Tahoe Impact: An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account Description: An authentication issue was addressed with improved state management. CVE-2026-20683: Lehan Dilusha Jayasingha (Sri Lanka), Jasminder Pal Singh, Dem0ns (@天府简易信工作室), Abdelhak Kherroubi Apple Neural Engine Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: An integer overflow was addressed with improved input validation. CVE-2026-65408: tamdao AppleAVD Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65407: Franco Belman at Blackwing Intelligence AppleDouble Available for: macOS Tahoe Impact: Mounting a disk image with maliciously crafted files may lead to unexpected system termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84519: Richard Zana AppleMobileFileIntegrity Available for: macOS Tahoe Impact: A malicious app may be able to break out of its sandbox Description: A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. CVE-2026-65381: Mickey Jin (@patch1t) ATS Available for: macOS Tahoe Impact: An app may be able to read files outside of its sandbox Description: A permissions issue was addressed by removing the vulnerable code. CVE-2026-43763: Pavan Nallamothu, Jared Reyes ATS Available for: macOS Tahoe Impact: An app may be able to access user-sensitive data Description: A logging issue was addressed with improved data redaction. CVE-2026-84525: D4rthL ATS Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with improved validation. CVE-2026-65342: Mohamad Dawoud / Abodi Dawoud, Ahmed Alwardani AuthKit Available for: macOS Tahoe Impact: A local app may be able to read a persistent account identifier Description: A permissions issue was addressed with additional restrictions. CVE-2026-84583: Zhongcheng Li from IES Red Team autofs Available for: macOS Tahoe Impact: An attacker with control of a network directory server may be able to execute arbitrary code with root privileges Description: A path traversal issue was addressed with improved path validation. CVE-2026-84568: Mr.Gedik (@h4ck2s3c) of Turkish Technology autofs Available for: macOS Tahoe Impact: An app may be able to bypass Gatekeeper checks Description: A logic issue was addressed with improved checks. CVE-2026-84570: Mr.Gedik (@h4ck2s3c) Automator Available for: macOS Tahoe Impact: An app may be able to break out of its sandbox Description: An authorization issue was addressed with improved state management. CVE-2026-84535: Sindre Sorhus, Oren Yomtov, Morris Richman (@morrisinlife), Kun Peeks (@SwayZGl1tZyyy) AVEVideoEncoder Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: The issue was addressed with improved checks. CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic Research AVEVideoEncoder Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A type confusion issue was addressed with improved memory handling. CVE-2026-84616: Peter Malone AVEVideoEncoder Available for: macOS Tahoe Impact: A sandboxed app may be able to execute arbitrary code with kernel privileges Description: A race condition was addressed with improved state management. CVE-2026-84607: Ruslan Dautov BackgroundAssets Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: A logic issue was addressed with improved validation. CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security Bluetooth Available for: macOS Tahoe Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65414 cd9660 Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: The issue was addressed with improved memory handling. CVE-2026-84567: Sanny Mitra, Sihyun Roh (Compsec, SNU), ngockhanh from Cystack, 정우 하 (@0xfa11babe), Suresh Sundaram, Surej Sekhar, Kun Peeks (@SwayZGl1tZyyy), Hari Shanmugam (The Hxr1), Ataberk Yavuzer copyfile Available for: macOS Tahoe Impact: An archive may be able to bypass Gatekeeper Description: A file quarantine bypass was addressed with additional checks. CVE-2026-65399: Rishabh Jain (rjcyber) of cyberplanet, Pasquale Scola, an anonymous researcher Core Bluetooth Available for: macOS Tahoe Impact: An app may be able to access Bluetooth device information Description: An authorization issue was addressed with improved state management. CVE-2026-86891: Dawuge of Shuffle Team CoreDrag Available for: macOS Tahoe Impact: An app may be able to cause unexpected process termination or disclose process memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-43683: Nathaniel Oh (@calysteon) CoreMedia Available for: macOS Tahoe Impact: An app may be able to access user-sensitive data Description: An access issue was addressed with additional sandbox restrictions. CVE-2026-43789: 이재영 CoreMedia Available for: macOS Tahoe Impact: Processing a maliciously crafted video file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65344: Siyeong kim CoreMedia Available for: macOS Tahoe Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-86876: Chris Bailey - Short Circuit CoreMedia Video Toolbox Available for: macOS Tahoe Impact: Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory Description: The issue was addressed with improved memory handling. CVE-2026-43702: Nathaniel Oh (@calysteon) CoreML Available for: macOS Tahoe Impact: A sandboxed app may be able to access restricted files Description: A permissions issue was addressed with improved path validation. CVE-2026-84624: AL Najafi, tamdao CoreMotion Available for: macOS Tahoe Impact: An app may be able to access motion data from headphones without user consent Description: An authorization issue was addressed with improved validation. CVE-2026-43737: Stuart Wallace CoreServices Available for: macOS Tahoe Impact: An app may be able to bypass Privacy preferences Description: A permissions issue was addressed with improved state management. CVE-2026-84574: Mickey Jin (@patch1t) CoreServices Available for: macOS Tahoe Impact: An app may bypass Gatekeeper checks Description: A logic issue was addressed with improved checks. CVE-2026-28899: Kraken Cryptocurrency Exchange, Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs CoreServices Available for: macOS Tahoe Impact: A malicious application may be able to access restricted files Description: A permissions issue was addressed with improved validation. CVE-2026-84559: Ryan Hughes CoreServices Available for: macOS Tahoe Impact: An app may be able to gain root privileges Description: This issue was addressed with additional entitlement checks. CVE-2026-43786: Kujtim Kryeziu (Sentry) CoreText Available for: macOS Tahoe Impact: Processing web content may lead to a denial-of-service Description: A null pointer dereference was addressed with improved input validation. CVE-2026-65412: Pavan Nallamothu CoreTypes Available for: macOS Tahoe Impact: A malicious app may be able to break out of its sandbox Description: A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. CVE-2026-65381: Mickey Jin (@patch1t) CoreUI Available for: macOS Tahoe Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re) CoreUI Available for: macOS Tahoe Impact: Processing a maliciously crafted asset catalog may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84511: stratan (@5tratan), Rahul Raj CUPS Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A logic issue was addressed with improved checks. CVE-2026-84563: Yongyue WANG AKA Brian.W of OKX security, Omar Cerrito CUPS Available for: macOS Tahoe Impact: An app may be able to gain elevated privileges Description: A path handling issue was addressed with improved validation. CVE-2026-64790: Aaron Grattafiori - NVIDIA AI Red Team CUPS Available for: macOS Tahoe Impact: A remote user may cause an unexpected app termination or arbitrary code execution Description: A validation issue was addressed with improved input sanitization. CVE-2026-43692: Aaron Grattafiori - NVIDIA AI Red Team CUPS Available for: macOS Tahoe Impact: An attacker in a privileged network position may be able to cause a denial-of-service Description: An integer overflow was addressed with improved input validation. CVE-2026-84554: Meshaal @ Darkcov, Joseph Shamoon CUPS Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-84540: Yongyue WANG AKA Brian.W of OKX security, 章鱼哥@aipy (aipyaipy.com), instantraaamen (github.com/instantraaamen) Contact: masa.shiramizu () gmail com CUPS Available for: macOS Tahoe Impact: An app may be able to gain root privileges Description: A path handling issue was addressed with improved validation. CVE-2026-43691: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs CUPS Available for: macOS Tahoe Impact: Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84516: 章鱼哥@aipy (aipyaipy.com) CUPS Available for: macOS Tahoe Impact: An app may be able to gain root privileges Description: An injection issue was addressed with improved validation. CVE-2026-43698: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs CUPS Available for: macOS Tahoe Impact: An application may be able to access restricted files Description: An input validation issue was addressed with improved input validation. CVE-2026-84541: 章鱼哥@aipy (aipyaipy.com) DeviceCheck Available for: macOS Tahoe Impact: An app may be able to read persistent device identifiers Description: An authorization issue was addressed with improved access control. CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill (@jjtech@infosec.exchange) Directory Utility Available for: macOS Tahoe Impact: An app may be able to gain root privileges Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84505: Tommy DeVoss from Braze Security Team (@thedawgyg) Disk Images Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: The issue was addressed with improved memory handling. CVE-2026-84552: Tommy DeVoss from Braze Security Team (@thedawgyg), PETOWORKS의 Bugeun Choi (@Bugeun), Peter Malone, Hyunwoo Kim (@v4bel), flower xu, Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research), Adriatik Raci Disk Images Available for: macOS Tahoe Impact: Processing a maliciously crafted disk image may lead to unexpected app termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84565: Nathaniel Oh (@calysteon) Disk Images Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with additional validation. CVE-2026-84550: Hyunwoo Kim (@v4bel), Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research) Disk Images Available for: macOS Tahoe Impact: An app may be able to gain root privileges Description: This issue was addressed with improved checks. CVE-2026-65362: Manish Bhatt, Amazon Leo Security, Nathaniel Oh (@calysteon), Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs, Adriatik Raci Disk Images Available for: macOS Tahoe Impact: Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-84512: Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research) exFAT Available for: macOS Tahoe Impact: Mounting a maliciously crafted volume may lead to unexpected system termination Description: A heap buffer overflow was addressed with improved bounds checking. CVE-2026-84510: Richard Zana, Meta Red Team X - Nik Tsytsarkin File Bookmark Available for: macOS Tahoe Impact: An app may be able to modify a file it only had permission to read Description: A permissions issue was addressed with additional restrictions. CVE-2026-43785: Junyeong Lee (jylab.github.io), Merrick Hare, Narendra Singh (@_3P1C), John Nzyuko Uvyu, Aditya Kumar file_cmds Available for: macOS Tahoe Impact: Extracting a maliciously crafted archive may allow an attacker to write arbitrary files Description: A path handling issue was addressed with improved validation. CVE-2026-84534: Geoffrey Lovelace FontParser Available for: macOS Tahoe Impact: Processing a maliciously crafted font file may lead to unexpected app termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84524: an anonymous researcher Foundation Available for: macOS Tahoe Impact: An app may be able to cause a denial of service Description: A type confusion issue was addressed with improved memory handling. CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research Game Center Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with improved validation. CVE-2026-84618: Luke Symons Graphics Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with improved state handling. CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg), Jiyong Yang Heimdal Available for: macOS Tahoe Impact: A user in a privileged network position may be able to leak sensitive user information Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org. CVE-2022-3437: Roman Zabicki HFS Available for: macOS Tahoe Impact: Mounting a malicious disk image may cause unexpected system termination Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-28934: Arni Hardarson (Neonix Security), Tristan Madani (@TristanInSec) from Talence Security, 정우 하, Aswin Kumar Gokulakannan, Peter Malone, Dun HFS Available for: macOS Tahoe Impact: Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-84581: Jonathan Bar Or (@yo_yo_yo_jbo), Feng Xue and XGPT of ThreatBook, Alfredo Pesoli (@__rev) of Bynar.io Image Capture Available for: macOS Tahoe Impact: An app may be able to access user-sensitive data Description: A path handling issue was addressed with improved validation. CVE-2026-64756: Luke Symons ImageIO Available for: macOS Tahoe Impact: Processing a maliciously crafted image may result in disclosure of process memory Description: An uninitialized memory issue was addressed with improved memory initialization. CVE-2026-84564: Justin O'Leary ImageIO Available for: macOS Tahoe Impact: Processing a maliciously crafted image may result in memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan IOGPUFamily Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with improved state handling. CVE-2026-43743: Lyutoon, Dun IOKit Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영 Kernel Available for: macOS Tahoe Impact: A local attacker may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-84566: Bernhard Jackiewicz Kernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-28968: Svetoslav Stolarov & Aisa Fox, Josh Maine of Calif.io, genter0, Dun Kernel Available for: macOS Tahoe Impact: Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84549: Surya Narayan Kushwaha, Aswin Kumar Gokulakannan Kernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination or write kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84619: James Duffy (@0x4A616D657344), genter0, Eddy Tsalolikhin Kernel Available for: macOS Tahoe Impact: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-43790: Omar Cerrito Kernel Available for: macOS Tahoe Impact: An app with root privileges may be able to read uninitialized kernel memory Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.) Kernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A memory corruption issue was addressed with improved memory handling. CVE-2026-65377: Ye Zhang (@VAR10CK) of Baidu Security, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Tahoe Impact: A malicious application may bypass Gatekeeper checks Description: A logic issue was addressed with improved state management. CVE-2026-65369: an anonymous researcher Kernel Available for: macOS Tahoe Impact: Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory Description: An integer overflow was addressed with improved input validation. CVE-2026-84544: Surya Narayan Kushwaha, Abhijeet Singh (www.linkedin.com/in/abhiunix/) Kernel Available for: macOS Tahoe Impact: Connecting to a malicious NFS server may disclose kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-43687: R4mbb of KRsecurity, Peter Malone Kernel Available for: macOS Tahoe Impact: An app may be able to gain root privileges Description: A permissions issue was addressed with additional restrictions. CVE-2026-86917: Hiroki Imai (LAC Co., Ltd.) Kernel Available for: macOS Tahoe Impact: Connecting to a malicious NFS server may lead to kernel memory corruption Description: A use-after-free issue was addressed with improved memory management. CVE-2026-43686: Peter Malone Kernel Available for: macOS Tahoe Impact: A remote attacker may be able to cause a denial-of-service Description: A denial-of-service issue was addressed with improved input validation. CVE-2026-84538: Stuart Thomas Kernel Available for: macOS Tahoe Impact: A remote attacker may be able to cause unexpected system termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-65364: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Tahoe Impact: An app may be able to determine kernel memory layout Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with improved state handling. CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-65401: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Tahoe Impact: An app may be able to disclose kernel memory Description: An information disclosure issue was addressed with improved memory management. CVE-2026-84530: Vladislav Shevchenko (Positive Technologies) Kernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A type confusion issue was addressed with improved checks. CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-84521: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A race condition was addressed with improved state handling. CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: An integer overflow was addressed with improved input validation. CVE-2026-84517: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A double free issue was addressed with improved memory management. CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati Kernel Available for: macOS Tahoe Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kext Management Available for: macOS Tahoe Impact: An app may be able to modify protected parts of the file system Description: This issue was addressed with additional entitlement checks. CVE-2026-84514: Mohamed Wedatalla, Nathaniel Oh (@calysteon), Arjanit Isufi Keychain Access Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved access control. CVE-2026-84556: Peter Malone, HvxyZLF, Chris Bailey - Short Circuit, Adrián Díaz Aguilar LaunchServices Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: A parsing issue in the handling of directory paths was addressed with improved path validation. CVE-2026-65382: an anonymous researcher libxpc Available for: macOS Tahoe Impact: An app may be able to bypass sandbox restrictions Description: An access issue was addressed with additional sandbox restrictions. CVE-2026-84577: Dave G. and Alex Radocea of supernetworks.org Mail Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved checks. CVE-2026-84573: Dawuge of Shuffle Team Mail Available for: macOS Tahoe Impact: An attacker in a privileged network position may be able to leak sensitive user information Description: A logic issue was addressed with improved checks. CVE-2026-43787: Armend Gashi Messages Available for: macOS Tahoe Impact: An app may be able to access protected user data Description: A logic issue was addressed with improved state management. CVE-2026-43741: Dawuge of Shuffle Team MobileAccessoryUpdater Available for: macOS Tahoe Impact: Connecting a malicious accessory may cause unexpected system termination Description: A memory corruption issue was addressed with improved input validation. CVE-2026-86924: Matthew Zamat Model I/O Available for: macOS Tahoe Impact: Opening a maliciously crafted file may lead to unexpected process termination Description: A buffer overflow was addressed with improved size validation. CVE-2026-84497: Yiğit Can YILMAZ (@yilmazcanyigit) NetworkExtension Available for: macOS Tahoe Impact: An app may be able to identify what other apps a user has installed Description: An information disclosure issue was addressed with improved state management. CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team NetworkExtension Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos odproxyd Available for: macOS Tahoe Impact: An app may be able to gain root privileges Description: This issue was addressed with improved checks. CVE-2026-64712: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs quarantine Available for: macOS Tahoe Impact: An app may be able to break out of its sandbox Description: The issue was addressed with improved checks. CVE-2026-84580: an anonymous researcher quarantine Available for: macOS Tahoe Impact: An app may be able to break out of its sandbox Description: A logic issue was addressed with improved checks. CVE-2026-84578: Kenneth Chew QuartzCore Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved checks. CVE-2026-84576: Dora Orak, @Ethan Arbuckle, and @leptos_null Quick Look Available for: macOS Tahoe Impact: Processing a maliciously crafted document may lead to an out-of-bounds read Description: An integer overflow was addressed with improved input validation. CVE-2026-84548: Peter Malone RealityKit Available for: macOS Tahoe Impact: Opening a maliciously crafted file may cause unexpected process termination or disclose process memory Description: An out-of-bounds read issue was addressed with improved input validation. CVE-2026-84532: stratan (@5tratan), Hongsik Kim (mnur) RealityKit Available for: macOS Tahoe Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-28966: stratan (@5tratan) Reminders Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved checks. CVE-2026-65403: Rahul Raj SceneKit Available for: macOS Tahoe Impact: Processing a maliciously crafted file may result in disclosure of process memory Description: An integer overflow was addressed with improved input validation. CVE-2026-84487: stratan (@5tratan), Peter Malone, Dhiyanesh Selvaraj (@redroot97) SceneKit Available for: macOS Tahoe Impact: An app may be able to cause a denial of service Description: An integer overflow was addressed with improved input validation. CVE-2026-65413: Peter Malone SceneKit Available for: macOS Tahoe Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter Malone CVE-2026-84611: Nathaniel Oh (@calysteon) SceneKit Available for: macOS Tahoe Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: The issue was addressed with improved memory handling. CVE-2026-84632: Peter Malone SceneKit Available for: macOS Tahoe Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: An integer overflow was addressed with improved input validation. CVE-2026-84620: Peter Malone SceneKit Available for: macOS Tahoe Impact: Processing a maliciously crafted 3D file may lead to an out-of-bounds read Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-43697: Peter Malone SceneKit Available for: macOS Tahoe Impact: Processing a maliciously crafted 3D scene may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84526: stratan (@5tratan) Screen Sharing Server Available for: macOS Tahoe Impact: An app may be able to access user-sensitive data Description: An access issue was addressed with improved access restrictions. CVE-2026-43760: Alfredo Pesoli (@__rev) of Bynar.io, wdszzml and Atuin Automated Vulnerability Discovery Engine Screen Sharing Server Available for: macOS Tahoe Impact: An attacker on the network may be able to authenticate to Screen Sharing without valid credentials Description: An authentication issue was addressed with improved state management. CVE-2026-65400: Alfredo Pesoli (@__rev) via Bynario Atlas (bynar.io) Security Available for: macOS Tahoe Impact: An attacker in a privileged network position may be able to intercept network traffic Description: A certificate validation issue was addressed with improved certificate validation. CVE-2026-86889: Jaeho Nam, Jungbum Lee, Sangwi Kang, Hyeonguk Ko and Taekyoung Kwon from SNU CSE MMLAB (mmlab.snu.ac.kr) Security Available for: macOS Tahoe Impact: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages Description: A certificate validation issue was addressed with improved certificate validation. CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier, Filip Olszak SMB Available for: macOS Tahoe Impact: Mounting a maliciously crafted SMB network share may lead to system termination Description: A use-after-free issue was addressed with improved memory management. CVE-2026-43719: Jakob Pammer, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research SMB Available for: macOS Tahoe Impact: Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds access issue was addressed with improved bounds checking. CVE-2026-84543: Peter Malone SMB Available for: macOS Tahoe Impact: A local user may be able to read kernel memory Description: A race condition was addressed with improved locking. CVE-2026-43690: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research SMB Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-65376: 재영 정, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research SMB Available for: macOS Tahoe Impact: Connecting to a malicious SMB server may lead to unexpected system termination Description: An integer underflow was addressed with improved input validation. CVE-2026-84536: 재영 정, Peter Malone, Feng Xue and XGPT of ThreatBook SMB Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-84537: Peter Malone, Feng Xue and XGPT of ThreatBook SMB Available for: macOS Tahoe Impact: Connecting to a malicious SMB share may disclose kernel memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-65365: Jay Patel, Peter Malone SMB Available for: macOS Tahoe Impact: Connecting to a malicious SMB server may lead to kernel memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84515: 재영 정, Peter Malone SMB Available for: macOS Tahoe Impact: Connecting to a malicious SMB server may lead to unexpected system termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84509: Dave G. smbx Available for: macOS Tahoe Impact: A remote attacker may be able to cause a denial-of-service Description: A resource exhaustion issue was addressed with improved input validation. CVE-2026-84553: Stuart Thomas Software Update Available for: macOS Tahoe Impact: An app may be able to modify protected system files Description: A permissions issue was addressed with improved path validation. CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team SoftwareUpdate Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved checks. CVE-2026-65361: Rodolphe BRUNETTI (@eisw0lf) of Lupus Nova Spotlight Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-65378: Sindre Sorhus, Abodi Dawoud, 糖豆爸爸(@晴天组织), Robert Mindo, Niels Hofmans Spotlight Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved access control. CVE-2026-84621: Abodi Dawoud, Ujjwal Reddy Kalvolu Sreenivasa Reddy, Johan Wahyudi, Armend Gashi Storage Available for: macOS Tahoe Impact: An app may be able to access user-sensitive data Description: A permissions issue was addressed with additional restrictions. CVE-2026-65345: 이재영, Seung Je Seong, Jakob Pammer, Ilya Andr (andrd3v) of Positive Technologies Storage Available for: macOS Tahoe Impact: An app may be able to modify protected parts of the file system Description: A permissions issue was addressed with additional restrictions. CVE-2026-65348: Jérôme Djouder StorageKit Available for: macOS Tahoe Impact: An app may be able to read arbitrary files Description: A validation issue was addressed with improved input sanitization. CVE-2026-43791: Amy (amys.website), Meridian Miftari, Aaron Grattafiori - - NVIDIA AI Red Team Symptom Framework Available for: macOS Tahoe Impact: A malicious application may be able to determine a user's current location Description: A privacy issue was addressed with improved private data redaction for log entries. CVE-2026-84513: Sindre Sorhus TCC Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: A logging issue was addressed with improved data redaction. CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom udf Available for: macOS Tahoe Impact: An app may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84572: Tomi (tk0) Koski (@tomikoski), Hari Shanmugam (The Hxr1) udf Available for: macOS Tahoe Impact: An app may be able to execute arbitrary code with kernel privileges Description: A use after free issue was addressed with improved memory management. CVE-2026-84506: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. WebDAV Available for: macOS Tahoe Impact: Connecting to a malicious WebDAV server may lead to unexpected app termination Description: An out-of-bounds write issue was addressed by removing the vulnerable code. CVE-2026-43677: bubu, Surya Narayan Kushwaha, Roman Zabicki, Richard Zana, Omar Cerrito, HE WEI(ギカク), Chris Bailey - Short Circuit, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research, Aswin Kumar Gokulakannan WebDAV Available for: macOS Tahoe Impact: Connecting to a malicious WebDAV server may result in code execution Description: A memory corruption issue was addressed with improved validation. CVE-2026-65374: He Wei(ギカク), Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research XPC Available for: macOS Tahoe Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-84617: Stuart Wallace Additional recognition AVEVideoEncoder We would like to acknowledge tamdao for their assistance. Bluetooth We would like to acknowledge Suresh Sundaram for their assistance. Calendar We would like to acknowledge Dany Assuid, Jacob Hazak from Zero-Defense Labs, Varik Matevosyan, stratan (@5tratan) for their assistance. dcerpc We would like to acknowledge Surya Narayan Kushwaha for their assistance. Kernel We would like to acknowledge Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Nebula Security (@nebusecurity) for their assistance. quarantine We would like to acknowledge an anonymous researcher for their assistance. Quick Look We would like to acknowledge Peter Malone for their assistance. rapportd We would like to acknowledge Tae Woo Kim for their assistance. Shortcuts We would like to acknowledge Owen Pawling (@owenpawling) for their assistance. Virtualization We would like to acknowledge Ye Zhang (@VAR10CK) of Baidu Security for their assistance. WindowServer We would like to acknowledge Jex Amro for their assistance. xar We would like to acknowledge Matthew Dean for their assistance. macOS Tahoe 26.7 may be obtained from the Mac App Store or Apple's Software Downloads web site: https://support.apple.com/downloads/ All information is also posted on the Apple Security Releases web site: https://support.apple.com/100100. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmqoYmEACgkQ4Ifiq8DH 7PUpnQ/8DIY96ykI3RtEeT54t+G8eZ8i089vJGsKeSY6FJF/CsYMYWPj/2mxPoCa YxUXduXbZWH71N2B6IhPEB0Tdx8cHV2YGnQET+crcyT+eNBzjvB2x+GnN6WhwsyG ZiSq6XjyHGqtj1SfnziEils+QH6arE5Gihu6bLuP+2EWwVhYd6SeSTER5XwEFCYw 384wDNFu00k9ke6QxaJLBJA42nNYqu2BMwjY+23VJ1tg6BlG/BsNq+1A9uZlEW3J g4X4YpIijZw6mhlHG4pjB7DpyBs5MMuxN0Yzw5MpbWCDKw98XoqDoUb9Bs/32IxL NKTrD8Gk5JwwP9jSJit+UKqRcP5KLw+WM5BhMp2uTyMcm5sX7H9VBL5tmCCU8FhI 3qozd8w+Lh03SKvPK+CJYgKENAMv7qOv2IIHY1KMCODHfA7xscDmRuH20Q2XstTF ECbM9SodyCmYIw+zglJxjGOwMEPle85n3YwBwpzxxOcJPF7ZhoKuQ8Q/gqSKilin PX4tMmFxuDE9tNxzQDfyifyG7j0B7ysBoU3kzhYEtrWxa/cNN1q/skImnQW1ERTg skQDuFpOoLiKd413aYoQH0a9HNBE1nJ+wgxxLPkSgRdwQCwLguZfv+U38ea9D8uK y8s+AXLEnPRV68SdfE96EAPLk6tsxiQYTqY3xbHrH4I9XFCSUAY= =7UTW -----END PGP SIGNATURE----- _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- APPLE-SA-09-14-2026-4 macOS Tahoe 26.7 Apple Product Security via Fulldisclosure (Sep 22)
