Developer

macOS Tahoe 26.5 Security Update Fixes Dozens of CVEs

Apple released macOS Tahoe 26.5, addressing numerous security vulnerabilities including a kernel bug (CVE-2026-28952) discovered by Calif.io in collaboration with Claude and Anthropic. The update fixes issues from denial-of-service to privilege escalation, sandbox escapes, and memory corruption. Multiple researchers and organizations are credited.

Neura News

Neura News

Neura Market Editorial

May 26, 20263 min read

Originally reported by support.apple.com

macOS Tahoe 26.5 Security Update Fixes Dozens of CVEs

Apple has released macOS Tahoe 26.5, a security update that patches a wide range of vulnerabilities across the operating system. The update addresses issues including kernel memory corruption, privilege escalation, sandbox escapes, and denial-of-service attacks.

One of the more notable vulnerabilities, CVE-2026-28952, is a kernel authorization issue that could allow an app to gain root privileges. The bug was discovered by Calif.io in collaboration with Claude and Anthropic Research. Apple fixed it with improved state management.

Key Vulnerabilities Addressed

The update includes fixes for multiple high-severity issues. CVE-2026-28923, reported by Kun Peeks, addresses a buffer overflow that could cause unexpected system termination or write kernel memory. CVE-2026-28925, from Aswin Kumar Gokula Kannan and Dave G., fixes an image processing bug that could corrupt process memory.

Several vulnerabilities could allow an app to break out of its sandbox. For example, CVE-2026-28995, credited to Vamshi Paili, Tony Gorez, and Reverse Society, is a logic issue addressed with improved restrictions. Another sandbox escape, reported by an anonymous researcher, was fixed with additional permissions restrictions.

Memory corruption issues are also prominent. CVE-2026-39869 from David Ige of Beryllium Security addresses a problem that could let an app access private information. Multiple use-after-free and out-of-bounds read/write bugs were fixed, including CVE-2026-28943 reported by Google Threat Analysis Group and CVE-2026-28969 by Mihalis Haatainen, Ari Hawking, and Ashish Kunwar.

Wide Range of Security Fixes

The update also addresses issues in networking, Wi-Fi, and Gatekeeper. CVE-2026-28929 from Yiğit Can YILMAZ fixes a denial-of-service vulnerability affecting local network attackers. Two other Wi-Fi related bugs, reported by Anton Pakhunov and Ricardo Prado (CVE-2026-43668) and Ian van der Wurff (CVE-2026-43666), were patched with improved bounds checking and input validation.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

Gatekeeper bypasses via maliciously crafted ZIP archives or disk images were fixed by Andreas Jaegersberger and Ro Achterberg of Nosebeard Labs (CVE-2026-28914) and another researcher. A race condition in Contacts access, CVE-2026-28924, was also addressed by the same team along with YingQi Shi.

Web content processing received multiple fixes. CVE-2026-28976, from David Ige, prevents Content Security Policy bypasses. Several use-after-free issues in Safari and WebKit were fixed, credited to researchers including Gia Bui (Calif.io), dr3dd, and w0wbox. CVE-2026-28942, found by Milad Nasr and Nicholas Carlini with Claude and Anthropic, addresses a malicious iframe that could misuse another website's download settings.

The update also includes fixes for privacy issues. CVE-2026-28940 from Michael DePlante of TrendAI Zero Day Initiative prevents an attacker with physical access from viewing sensitive user data. Another bug that could track users via IP address was resolved through improved state management.

Acknowledgments

Apple thanked a long list of researchers and organizations for their assistance. These include Mikael Kinnman, Asaf Cohen, Johan Wahyudi, Kun Peeks, YingQi Shi, Brian Carpenter, Andreas Jaegersberger and Ro Achterberg, Jordan Pittman, Mustafa Calap, and many others. Also acknowledged are Chris Staite and David Hardy of Menlo Security, Ilias Morad, Jason Grove, Jeffery Kimbrow, Asilbek Salimov, Anand Patil, Christopher Mathews, Cem Onat Karagun, Surya Kushwaha, sean mutuku, Robert Mindo, Yoav Magid, Muhammad Zaid Ghifari, Hyeonji Son, and others.

As per Apple's policy, the company does not disclose, discuss, or confirm security issues until after an investigation and patch release. Users are encouraged to update to macOS Tahoe 26.5 to protect against these vulnerabilities.

Related on Neura Market

More from Neura News

AI Models

Google Unveils Gemini 3.6 Flash, 3.5 Flash-Lite, and Cyber Model

Google has released three new Gemini models: 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber. The 3.6 Flash model offers improved coding and knowledge work with 17% fewer output tokens and lower costs. The 3.5 Flash-Lite is the fastest in the series at 350 tokens per second, designed for high-throughput agentic tasks. The 3.5 Flash Cyber model, available only to governments and trusted partners via CodeMender, focuses on finding and fixing cybersecurity vulnerabilities. Google also noted that Gemini 3.5 Pro is being tested with partners and that pre-training for Gemini 4 has begun.

Jul 21·5 min read
AI Models

Alibaba Qwen-Image-3.0 renders infographics and tiny text in one pass

Alibaba's Qwen team released Qwen-Image-3.0, an image generator designed for practical applications like newspaper layouts and complex infographics. The model processes prompts of up to 4,500 tokens and can render legible text as small as ten pixels, mathematical formulas, and twelve languages in a single pass. It is currently available through invite-only API access, with plans to integrate it into first-party apps like Qwen Chat soon.

Jul 21·4 min read
AI Models

Google Unveils Gemini 3.6 Flash, 3.5 Flash-Lite, and Cyber Model

Google DeepMind has introduced three new Gemini models: 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber. The 3.6 Flash model offers improved coding and multimodal performance with 17% fewer output tokens and lower cost. The 3.5 Flash-Lite is the fastest in its series at 350 output tokens per second, designed for high-throughput agentic tasks. The 3.5 Flash Cyber, fine-tuned for cybersecurity, will be available exclusively to governments and trusted partners via the CodeMender agent.

Jul 21·6 min read