NEWS
Apple’s 194-CVE Drop Quietly Shields Older Macs Too
macOS Tahoe 26.6 alone fixes 155 vulnerabilities while Sequoia and Sonoma get matching root and sandbox patches in the same July rollout.
Apple released macOS Tahoe 26.6, iOS 26.6, iPadOS 26.6 and companion updates on July 27, 2026, closing 194 unique vulnerabilities across its platforms after removing overlap. No active exploitation appears in the advisories.
The flagship numbers grab attention. The quieter security-only drops for macOS Sequoia 15.7.8 and Sonoma 14.8.8 close many of the same root and sandbox paths for the large share of Macs still off Tahoe.
The July 27 Numbers Across Every Device
macOS Tahoe 26.6 accounts for 155 unique CVEs on its own. iOS 26.6 and iPadOS 26.6 list more than 75 entries tied to roughly 87 unique identifiers. watchOS 26.6, tvOS 26.6 and visionOS 26.6 help push the de-duplicated total to 194. Safari 26.6 adds nearly a dozen WebKit and WebRTC fixes for older Macs.
- 155 unique CVEs in macOS Tahoe 26.6 alone
- 87 unique on the iOS and iPadOS side
- 194 unique after cross-platform overlap removal
- 0 reported in-the-wild exploits in current notes
Device support stays broad. iOS and iPadOS 26.6 reach iPhone 11 and later plus a long list of iPad Pro, Air, standard and mini models. watchOS covers Series 6 and later. tvOS and visionOS hit every current Apple TV and Vision Pro.
| Update | Approx. Unique CVEs | Key Targets |
|---|---|---|
| macOS Tahoe 26.6 | 155 | macOS Tahoe |
| iOS / iPadOS 26.6 | 87 | iPhone 11+, listed iPads |
| watchOS / tvOS / visionOS 26.6 | part of 194 total | Watch Series 6+, all Apple TV, Vision Pro |
| Safari 26.6 | ~12 | Sonoma and Sequoia |
| Sequoia 15.7.8 / Sonoma 14.8.8 | 138+ shared | Older still-supported Macs |
Apple’s own Apple security releases index lists every note under the July 27 date.

Tahoe’s 155-CVE Load
The macOS Tahoe 26.6 security content page runs long. Accounts, Apple Account, Audio, Core Services, CUPS, Disk Images and the kernel appear repeatedly.
Impacts include apps gaining root privileges, sandbox escapes, Gatekeeper bypasses, unauthorized contacts access, file deletion without permission, kernel memory reads and remote denial-of-service. Neural Engine entries cover out-of-bounds writes and use-after-free crashes. Buffer overflows and race conditions dominate the descriptions.
- Root privilege escalation via path parsing and race conditions
- Sandbox breaks in Audio, Apple Account and Game Center-style components
- Gatekeeper and code-signing bypasses
- Kernel memory corruption and disclosure via APFS, Disk Images and drivers
- Privacy leaks through Contacts, Crash Reporter and fingerprinting paths
Memory handling improvements and extra sandbox restrictions form the common fix pattern.
iPhone and iPad Close Their Own List
The iOS 26.6 and iPadOS 26.6 fixes hit Neural Engine, App Store, kernel, WebKit, Wi-Fi, Siri, ImageIO and Game Center. One physical-access issue around iPhone Mirroring appears early. ImageIO carries integer overflows that could lead to arbitrary code execution. Several sandbox and data-protection entries match the Mac side.
ApplSec tallies circulating on X put roughly 19 bugs in the kernel, 9 in Model I/O, 8 in WebKit and 6 in ImageIO among the larger groups. The update also optimizes the Spotlight index ahead of the next major release.
This follows the smaller earlier iOS 26.5.2 WebKit round that cleared 29 issues, most browser-related.
Older Macs Receive the Quiet Cover
Sequoia 15.7.8 and Sonoma 14.8.8 shipped the same day as security-only packages. Their notes reuse many of the same CVE identifiers that appear in Tahoe: Accounts root paths, APFS memory issues, Neural Engine crashes, CUPS privilege gains, Gatekeeper bypasses and Disk Images elevation.
Users who stayed on the prior two generations therefore receive the critical closures without a full OS jump. That installed base remains large. The backports turn a flagship event into something closer to fleet-wide maintenance.
Safari 26.6 lands on those same older Macs, so the browser engine stays current even if the base system does not move to Tahoe.
Safari 26.6 Tightens WebKit and WebRTC
The Safari 26.6 WebKit patches address improper authorization, memory disclosure, UI spoofing and clickjacking, iframe sandbox policy violations, use-after-free crashes and WebRTC out-of-bounds access. Roughly a dozen entries appear, several credited to external researchers and one team that used Claude from Anthropic.
These matter for any Mac still on Sonoma or Sequoia that browses untrusted sites. The same engine fixes travel with the mobile updates.
Privilege Escalation and Kernel Paths Lead
Across the set, the highest-impact descriptions cluster around local privilege gains, sandbox escapes and kernel memory issues. Remote code paths exist mainly through malicious media files or crafted web content. Fingerprinting and unauthorized data access fill out the middle tier.
The volume itself tracks the growth of shared frameworks. Neural Engine, modern media stacks and attestation components keep adding attack surface even as Apple ships monthly or bi-monthly drops. Prior bulk releases in 2026 already topped 130 CVEs; this one sets a fresh high-water mark by several researcher counts.
Researchers Filled Most of the Credits
Apple’s notes name dozens of external finders. Blackwing Intelligence, TrendAI Zero Day Initiative, CyStack, SpecterOps, Nosebeard Labs and individual handles such as @everping and @theevilbit appear often. One ZDI researcher posted that three of his reports landed in the Tahoe set and called the advisory “possibly Apple’s largest security advisory ever by CVE count.”
macOS 26.6 just shipped. Possibly Apple’s largest security advisory ever by CVE count.
Michael DePlante (@izobashi) wrote that after the release. AI-assisted discovery also surfaces: Claude from Anthropic received credit on at least one WebKit memory issue. The crowd layer on X treated the kernel concentration and the older-OS backports as the practical takeaway rather than pure CVE theater.
Install paths stay standard. On iPhone or iPad open Settings then General then Software Update. On Mac use System Settings then General then Software Update. Watch, TV and Vision Pro follow their own Settings menus. Automatic updates remain the simplest long-term habit.
The window without known exploitation will not last forever once the notes are public. The backports mean the large non-Tahoe fleet does not have to wait for a major upgrade to close the same holes.
Frequently Asked Questions
How many unique CVEs did macOS Tahoe 26.6 fix?
Apple’s security content lists 155 unique CVEs for macOS Tahoe 26.6, the single largest slice of the July 27 rollout and higher than several prior bulk updates in 2026.
Which iPhone models receive iOS 26.6?
iOS 26.6 supports iPhone 11 and every later model; older devices stay on their final supported major version and do not receive this drop.
Did Apple report any active exploitation of these flaws?
The current advisories state that Apple is not aware of any active exploitation of the vulnerabilities addressed in these updates at the time of release.
Do older Macs on Sequoia or Sonoma get the same critical fixes?
Yes. macOS Sequoia 15.7.8 and Sonoma 14.8.8 shipped the same day as security-only updates that close many identical root, sandbox and kernel paths listed in the Tahoe notes.
What does Safari 26.6 specifically address?
Safari 26.6 for Sonoma and Sequoia patches roughly a dozen WebKit and WebRTC issues covering memory disclosure, UI spoofing, iframe sandbox escapes, crashes and authorization flaws.
-
FINANCE2 months agoZcash Patched a Double-Spend Bug as ZEC Climbed 5%
-
ENTERTAINMENT2 months agoSteam Summer Sale 2026 Locks In June 25 to July 9 Dates
-
FINANCE4 weeks agoCLARITY Act Final Text Expected This Weekend as 60-Vote Hurdle Looms
-
NEWS3 months agoMeta Adds AI Replies to Threads, But Users Can’t Block It
-
ENTERTAINMENT2 months ago‘Widow’s Bay’ Review: Apple TV’s Sleeper Horror-Comedy Earns Its Fog
-
NEWS7 months agoFolderFresh Review: This Free Tool Automates Windows File Organizing
-
NEWS5 months agoU.S. Navy Deploys Solar-Powered Lightfish Drone to Patrol Oceans
-
FINANCE3 weeks agoKalshi Loses Major NY Prediction Markets Ruling to Judge Torres
