Apple has released macOS Tahoe 26.5, a security update that patches a wide range of vulnerabilities across the operating system. The update addresses issues including kernel memory corruption, privilege escalation, sandbox escapes, and denial-of-service attacks.
One of the more notable vulnerabilities, CVE-2026-28952, is a kernel authorization issue that could allow an app to gain root privileges. The bug was discovered by Calif.io in collaboration with Claude and Anthropic Research. Apple fixed it with improved state management.
Key Vulnerabilities Addressed
The update includes fixes for multiple high-severity issues. CVE-2026-28923, reported by Kun Peeks, addresses a buffer overflow that could cause unexpected system termination or write kernel memory. CVE-2026-28925, from Aswin Kumar Gokula Kannan and Dave G., fixes an image processing bug that could corrupt process memory.
Several vulnerabilities could allow an app to break out of its sandbox. For example, CVE-2026-28995, credited to Vamshi Paili, Tony Gorez, and Reverse Society, is a logic issue addressed with improved restrictions. Another sandbox escape, reported by an anonymous researcher, was fixed with additional permissions restrictions.
Memory corruption issues are also prominent. CVE-2026-39869 from David Ige of Beryllium Security addresses a problem that could let an app access private information. Multiple use-after-free and out-of-bounds read/write bugs were fixed, including CVE-2026-28943 reported by Google Threat Analysis Group and CVE-2026-28969 by Mihalis Haatainen, Ari Hawking, and Ashish Kunwar.
Wide Range of Security Fixes
The update also addresses issues in networking, Wi-Fi, and Gatekeeper. CVE-2026-28929 from Yiğit Can YILMAZ fixes a denial-of-service vulnerability affecting local network attackers. Two other Wi-Fi related bugs, reported by Anton Pakhunov and Ricardo Prado (CVE-2026-43668) and Ian van der Wurff (CVE-2026-43666), were patched with improved bounds checking and input validation.
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
Gatekeeper bypasses via maliciously crafted ZIP archives or disk images were fixed by Andreas Jaegersberger and Ro Achterberg of Nosebeard Labs (CVE-2026-28914) and another researcher. A race condition in Contacts access, CVE-2026-28924, was also addressed by the same team along with YingQi Shi.
Web content processing received multiple fixes. CVE-2026-28976, from David Ige, prevents Content Security Policy bypasses. Several use-after-free issues in Safari and WebKit were fixed, credited to researchers including Gia Bui (Calif.io), dr3dd, and w0wbox. CVE-2026-28942, found by Milad Nasr and Nicholas Carlini with Claude and Anthropic, addresses a malicious iframe that could misuse another website's download settings.
The update also includes fixes for privacy issues. CVE-2026-28940 from Michael DePlante of TrendAI Zero Day Initiative prevents an attacker with physical access from viewing sensitive user data. Another bug that could track users via IP address was resolved through improved state management.
Acknowledgments
Apple thanked a long list of researchers and organizations for their assistance. These include Mikael Kinnman, Asaf Cohen, Johan Wahyudi, Kun Peeks, YingQi Shi, Brian Carpenter, Andreas Jaegersberger and Ro Achterberg, Jordan Pittman, Mustafa Calap, and many others. Also acknowledged are Chris Staite and David Hardy of Menlo Security, Ilias Morad, Jason Grove, Jeffery Kimbrow, Asilbek Salimov, Anand Patil, Christopher Mathews, Cem Onat Karagun, Surya Kushwaha, sean mutuku, Robert Mindo, Yoav Magid, Muhammad Zaid Ghifari, Hyeonji Son, and others.
As per Apple's policy, the company does not disclose, discuss, or confirm security issues until after an investigation and patch release. Users are encouraged to update to macOS Tahoe 26.5 to protect against these vulnerabilities.
