Connect with us

NEWS

Apple’s 194-CVE Drop Quietly Shields Older Macs Too

macOS Tahoe 26.6 alone fixes 155 vulnerabilities while Sequoia and Sonoma get matching root and sandbox patches in the same July rollout.

Published

on

Apple released macOS Tahoe 26.6, iOS 26.6, iPadOS 26.6 and companion updates on July 27, 2026, closing 194 unique vulnerabilities across its platforms after removing overlap. No active exploitation appears in the advisories.

The flagship numbers grab attention. The quieter security-only drops for macOS Sequoia 15.7.8 and Sonoma 14.8.8 close many of the same root and sandbox paths for the large share of Macs still off Tahoe.

The July 27 Numbers Across Every Device

macOS Tahoe 26.6 accounts for 155 unique CVEs on its own. iOS 26.6 and iPadOS 26.6 list more than 75 entries tied to roughly 87 unique identifiers. watchOS 26.6, tvOS 26.6 and visionOS 26.6 help push the de-duplicated total to 194. Safari 26.6 adds nearly a dozen WebKit and WebRTC fixes for older Macs.

  • 155 unique CVEs in macOS Tahoe 26.6 alone
  • 87 unique on the iOS and iPadOS side
  • 194 unique after cross-platform overlap removal
  • 0 reported in-the-wild exploits in current notes

Device support stays broad. iOS and iPadOS 26.6 reach iPhone 11 and later plus a long list of iPad Pro, Air, standard and mini models. watchOS covers Series 6 and later. tvOS and visionOS hit every current Apple TV and Vision Pro.

Update Approx. Unique CVEs Key Targets
macOS Tahoe 26.6 155 macOS Tahoe
iOS / iPadOS 26.6 87 iPhone 11+, listed iPads
watchOS / tvOS / visionOS 26.6 part of 194 total Watch Series 6+, all Apple TV, Vision Pro
Safari 26.6 ~12 Sonoma and Sequoia
Sequoia 15.7.8 / Sonoma 14.8.8 138+ shared Older still-supported Macs

Apple’s own Apple security releases index lists every note under the July 27 date.

Tahoe’s 155-CVE Load

The macOS Tahoe 26.6 security content page runs long. Accounts, Apple Account, Audio, Core Services, CUPS, Disk Images and the kernel appear repeatedly.

Impacts include apps gaining root privileges, sandbox escapes, Gatekeeper bypasses, unauthorized contacts access, file deletion without permission, kernel memory reads and remote denial-of-service. Neural Engine entries cover out-of-bounds writes and use-after-free crashes. Buffer overflows and race conditions dominate the descriptions.

  • Root privilege escalation via path parsing and race conditions
  • Sandbox breaks in Audio, Apple Account and Game Center-style components
  • Gatekeeper and code-signing bypasses
  • Kernel memory corruption and disclosure via APFS, Disk Images and drivers
  • Privacy leaks through Contacts, Crash Reporter and fingerprinting paths

Memory handling improvements and extra sandbox restrictions form the common fix pattern.

iPhone and iPad Close Their Own List

The iOS 26.6 and iPadOS 26.6 fixes hit Neural Engine, App Store, kernel, WebKit, Wi-Fi, Siri, ImageIO and Game Center. One physical-access issue around iPhone Mirroring appears early. ImageIO carries integer overflows that could lead to arbitrary code execution. Several sandbox and data-protection entries match the Mac side.

ApplSec tallies circulating on X put roughly 19 bugs in the kernel, 9 in Model I/O, 8 in WebKit and 6 in ImageIO among the larger groups. The update also optimizes the Spotlight index ahead of the next major release.

This follows the smaller earlier iOS 26.5.2 WebKit round that cleared 29 issues, most browser-related.

Older Macs Receive the Quiet Cover

Sequoia 15.7.8 and Sonoma 14.8.8 shipped the same day as security-only packages. Their notes reuse many of the same CVE identifiers that appear in Tahoe: Accounts root paths, APFS memory issues, Neural Engine crashes, CUPS privilege gains, Gatekeeper bypasses and Disk Images elevation.

Users who stayed on the prior two generations therefore receive the critical closures without a full OS jump. That installed base remains large. The backports turn a flagship event into something closer to fleet-wide maintenance.

Safari 26.6 lands on those same older Macs, so the browser engine stays current even if the base system does not move to Tahoe.

Safari 26.6 Tightens WebKit and WebRTC

The Safari 26.6 WebKit patches address improper authorization, memory disclosure, UI spoofing and clickjacking, iframe sandbox policy violations, use-after-free crashes and WebRTC out-of-bounds access. Roughly a dozen entries appear, several credited to external researchers and one team that used Claude from Anthropic.

These matter for any Mac still on Sonoma or Sequoia that browses untrusted sites. The same engine fixes travel with the mobile updates.

Privilege Escalation and Kernel Paths Lead

Across the set, the highest-impact descriptions cluster around local privilege gains, sandbox escapes and kernel memory issues. Remote code paths exist mainly through malicious media files or crafted web content. Fingerprinting and unauthorized data access fill out the middle tier.

The volume itself tracks the growth of shared frameworks. Neural Engine, modern media stacks and attestation components keep adding attack surface even as Apple ships monthly or bi-monthly drops. Prior bulk releases in 2026 already topped 130 CVEs; this one sets a fresh high-water mark by several researcher counts.

Researchers Filled Most of the Credits

Apple’s notes name dozens of external finders. Blackwing Intelligence, TrendAI Zero Day Initiative, CyStack, SpecterOps, Nosebeard Labs and individual handles such as @everping and @theevilbit appear often. One ZDI researcher posted that three of his reports landed in the Tahoe set and called the advisory “possibly Apple’s largest security advisory ever by CVE count.”

macOS 26.6 just shipped. Possibly Apple’s largest security advisory ever by CVE count.

Michael DePlante (@izobashi) wrote that after the release. AI-assisted discovery also surfaces: Claude from Anthropic received credit on at least one WebKit memory issue. The crowd layer on X treated the kernel concentration and the older-OS backports as the practical takeaway rather than pure CVE theater.

Install paths stay standard. On iPhone or iPad open Settings then General then Software Update. On Mac use System Settings then General then Software Update. Watch, TV and Vision Pro follow their own Settings menus. Automatic updates remain the simplest long-term habit.

The window without known exploitation will not last forever once the notes are public. The backports mean the large non-Tahoe fleet does not have to wait for a major upgrade to close the same holes.

Frequently Asked Questions

How many unique CVEs did macOS Tahoe 26.6 fix?

Apple’s security content lists 155 unique CVEs for macOS Tahoe 26.6, the single largest slice of the July 27 rollout and higher than several prior bulk updates in 2026.

Which iPhone models receive iOS 26.6?

iOS 26.6 supports iPhone 11 and every later model; older devices stay on their final supported major version and do not receive this drop.

Did Apple report any active exploitation of these flaws?

The current advisories state that Apple is not aware of any active exploitation of the vulnerabilities addressed in these updates at the time of release.

Do older Macs on Sequoia or Sonoma get the same critical fixes?

Yes. macOS Sequoia 15.7.8 and Sonoma 14.8.8 shipped the same day as security-only updates that close many identical root, sandbox and kernel paths listed in the Tahoe notes.

What does Safari 26.6 specifically address?

Safari 26.6 for Sonoma and Sequoia patches roughly a dozen WebKit and WebRTC issues covering memory disclosure, UI spoofing, iframe sandbox escapes, crashes and authorization flaws.

As the founder of Thunder Tiger Europe Media, Dr. Elias Thornwood brings over 25 years of experience in international journalism, having reported from conflict zones in the Middle East, Asia, and Africa for outlets like BBC World and Reuters. With a PhD in International Relations from Oxford University, his expertise lies in geopolitical analysis and global diplomacy. Elias has authored two bestselling books on European foreign policy and received the Pulitzer Prize for International Reporting in 2015, establishing his authoritativeness in the field. Committed to trustworthiness, he enforces rigorous fact-checking protocols at Thunder Tiger, ensuring unbiased, evidence-based coverage of worldwide news to empower informed global audiences.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending