About the security content of macOS Tahoe 26.6(support.apple.com)
205 points by andor 1 day ago | 138 comments
tl;dr: Apple's macOS Tahoe 26.6 patches dozens of security vulnerabilities, including multiple root privilege escalations, sandbox escapes, kernel memory corruption bugs, Gatekeeper bypasses, and issues allowing apps to access sensitive user data or fingerprint users. Notable fixes include kernel-level arbitrary code execution (CVE-2026-64747), code signing bypass (CVE-2026-43813), and a file quarantine/Gatekeeper bypass (CVE-2026-64708). Credited researchers span independent hunters and firms like Blackwing Intelligence, SpecterOps, NVIDIA AI Red Team, and Nosebeard Labs.
HN Discussion:
  • Memory-safety bug patterns highlight the monetary cost of using unsafe languages
  • Notable prominence of AI/Claude collaboration in vulnerability credits
  • Full POSIX path handling in user-facing inputs creates unnecessary attack surface
  • ~Excessive collision counts and AI attributions in credits seem absurd
  • Users should be cautious upgrading due to Tahoe stability/usability issues