About the security content of macOS Tahoe 26.6

(support.apple.com)

154 points | by andor 5 hours ago ago

99 comments

  • TheJoeMan an hour ago ago

    This may be a naive take, so if anyone has insight please feel free to share, but across Windows, Mac, and Linux OS's I see many cases of path parsing vulnerabilities resulting in sandbox escapes, code execution, or data access issues. When presenting the user with a file picker or command-line input, is it really needed that the software can handle the full POSIX spec?

    I do not see a "typical" user needing to access a path with say a network storage but multiple ../.. and hard and soft symlinks simultaneously. I think "be liberal in what you accept" might need to be revisited for path parsing with some sort of OS-wide single-implementation as an optional feature.

    • catlifeonmars 14 minutes ago ago

      How would you enforce a single implementation of path parsing?

    • acuozzo 9 minutes ago ago

      > I do not see a "typical" user needing to access a path with say...

      Typical users run software written by atypical users.

      > some sort of OS-wide single-implementation

      How do you propose handling migration? What if someone tries to expand an old archive file containing a now-forbidden path?

  • tengwar2 3 hours ago ago

    15.7.8 is out today as well, with these security fixes: https://support.apple.com/en-us/128071.

    For context, there have been issues with MacOS 26 which have led many people to defer upgrading until MacOS 27 is available, and MacOS 15 is the previous version.

    • jghn 3 hours ago ago

      > For context, there have been issues with MacOS 26 which have led many people to defer upgrading

      For me the issue is liquid glass. Which I doubt is getting fixed any time soon

      • pmdr 11 minutes ago ago

        I bought a MBP mainly for the hardware, otherwise I'd have stuck with Linux. OS-wise, the jump from Monterey (which I'd last used) to Sequoia was smooth and still feels that way. I prefer not to notice the OS at all, something that I feel would be hard to do on Tahoe due to all that liquid glass and dumb transparency and animations.

        Seriously, who the heck even asked for those?

      • illithid0 3 hours ago ago

        Also a liquid glass hater, but for what it's worth, 27 is supposed to make it a little bit better. I would prefer to go back to what I had before I had to upgrade into this horrible UI, but this is better than nothing.

        https://www.cultofmac.com/news/liquid-glass-changes-ios-27-m...

        • hbn 2 hours ago ago

          I've been running the 27 beta and it fixes so much of the ugliness I hated in Tahoe. Lots of places had toolbars restored, solid areas that indicate where the window can be grabbed. The shitty icon spam in menus is back to sanity. And window corner radii are consistent and less bulbous.

        • noname120 an hour ago ago

          macOS 17 is decisively faster on my MacBook Air M1 16 GB than macOS 26/27 is on my MacBook Pro M2 Max 32 GB. And I don’t mean just the animations themselves but lag/sluggishness/responsiveness in general.

        • trollbridge 2 hours ago ago

          You can almost turn it off on the 27 beta, and 27 seems to perform a lot better too.

          • flohofwoe 2 hours ago ago

            You can already turn off most glass effects in 26 via "System Settings => Accessibility => Display => Reduce Transparency".

            I had that turned off years ago (for reasons I don't remember), and was wondering what all the fuzz was about when 26 came out because I didn't see much of a difference ;)

            IMHO the actual important visual changes in the 27 beta is that rolls back the bizarre oversized corner radius in Finder windows, and they also got rid of the 'every menu item must have an icon' idea.

            • trollbridge 2 hours ago ago

              27 seems superior to 26 in almost every way, although I'm still on a fairly old beta.

            • SanjayMehta an hour ago ago

              It's the first thing I turn off on a new iPhone or iPad. Started around ten years ago in the release which had animated app icons. Induced nausea.

        • lapcat 3 hours ago ago

          > this is better than nothing.

          Having installed the beta, I think that's the best you can say about it.

          • etempleton 2 hours ago ago

            Also on the beta. Agreed. Definite visual and UX improvement over 26, fixing the most egregious issues with 26 implementation of Liquid Glass, but maybe not quite as good as 25 overall.

            • lapcat 2 hours ago ago

              > not quite as good as 25 overall

              Nothing will ever be as good as 25.

              Because macOS 25 does not exist. ;-)

          • Jolter 2 hours ago ago

            I hear it’s slower? Can you comment on that?

            • Tagbert an hour ago ago

              The 27 betas? No, they are generally faster than 26.

            • lapcat 2 hours ago ago

              I haven't noticed or heard that it's slower.

          • illithid0 3 hours ago ago

            As long as the UI improves and I can ignore all the AI stuff they're starting to push through, that's fine with me, though like many longtime macOS users, I'm not holding my breath for a bug-free experience.

            • ChrisMarshallNY 5 minutes ago ago

              > AI stuff they're starting to push through

              iOS 26 anecdote:

              A couple of weeks ago, I had a Baltimore Oriole (a cool-looking bird, not a baseball player) in my yard. They aren't rare, per se, but they are uncommon.

              Took my iPhone out to snap a picture, and pressed the camera button. I hadn't used it, since upgrading to 26.

              It takes the picture. It's there. I can see it, but it won't let me save it. Instead, it wants to tell me about the cool new voice-activated AI retouch feature. There was no way to save.

              I probably could have figured it out, but I was so furious, I just nuked the picture.

            • dylan604 an hour ago ago

              > though like many longtime macOS users

              For those of us older than just 10 years of using macOS, the older Apple OSes have instilled within us the desire to never install the X.0 release and wait until at least the X.1 release. The bug-free experience is a myth

      • Hamuko 2 hours ago ago

        Same. It's not the worst thing in the world, at least with Reduce Transparency enabled in the Accessibility settings, but I still don't feel any inclination to upgrade. My personal Mac Studio is macOS 15 and my work MacBook is on macOS 26, and I don't think there's a single thing that I find to be better on the work laptop than on my personal machine.

        I might update to macOS 26 in September to be ready to update to macOS 27. Being two versions behind doesn't seem reasonable and I'd rather be on the "Tahoe but less shitty" version than Tahoe itself.

      • frizlab 2 hours ago ago

        macOS 27 does polish Liquid Glass and makes it look passable on macOS IMHO. It was very bad on 26. Comically bad.

        • reddalo an hour ago ago

          That's the sad thing: Apple decided to leave all Intel macs on broken macOS 26. Very bad on Apple's part.

      • IdiotSavage an hour ago ago

        I hate the round corners. It's already too much on 15, but way worse on 26. It looks like "Baby's first OS", designed by Fisher-Price.

        • hbn an hour ago ago
          • ak217 an hour ago ago

            Love to see this, now if only they could revert the whole shimmering oil slick disaster that is "glass" on iOS (unlike macOS, even if I "reduce transparency", the oil slick effect still appears in many places, in addition to all the spacing issues).

      • simlevesque an hour ago ago

        You can disable it in the accessibility preferences.

    • embedding-shape 3 hours ago ago

      Same thing happens almost every release. I've stopped updating my Mac machine until I see something in the release notes I literally have to have in order to continue doing macOS/iOS builds, otherwise I'm staying on the version I've validated to work, and I know the existing bugs with.

      • DavideNL an hour ago ago

        A better strategy would probably be to stick with the previous *major* release, but, do install its ("minor") security updates...

        • embedding-shape an hour ago ago

          > do install its ("minor") security updates

          Yeah, I thought so too, but surprise surprise; some months ago one of the "minor" updates "broke" ("upgraded") something that made my CI/CD setup stop working, that's when I dropped the idea that Apple even do "minor" updates anymore.

    • gokohl 2 hours ago ago

      I still haven’t upgraded because of the UI issues. Curious though how long we will still see this large amount of CVE. My guess was always that we will see much more robust and secure software now with AI assisted engineering but probably still same amount of hacks. Is there a related law already describing this?

    • reddalo an hour ago ago

      >have led many people to defer upgrading until MacOS 27 is available

      Then there's me, crying in MacBook Pro 2019 stuck on MacOS 15 because 27 won't be available for my machine.

    • bouke 2 hours ago ago

      The question now is, is 27 sufficient enough of an improvement over 15 to upgrade and tolerate Liquid Glass?

    • ExoticPearTree 3 hours ago ago

      26.0 had a very annoying video jitter issue, but that was the first things that I noticed to be fixed in the next 26 release. Other than that, it worked just fine.

      • andreasley 3 hours ago ago

        The bug that led to network connection issues after 49 days of uninterrupted uptime was a bit of a showstopper for me.

    • carra 2 hours ago ago

      Are there no versions between MacOS 15 and 26???

      • kylemaxwell 2 hours ago ago

        They changed the numbering scheme, so... no, there aren't. Version numbers are now year-based, but previously they were not.

      • hbn 2 hours ago ago

        Last year they unified all their OS version numbers to just match upcoming year.

        macOS went from 15 to 26

        iOS went from 18 to 26

        watchOS went from 11 to 26

        and so on

      • classified 44 minutes ago ago

        No, 26 is the successor of 15. They changed the numbering to year-based.

    • crossroadsguy 2 hours ago ago

      Did they un-hardcode the corner radius? I mean were they able to? I mean not that that anyone at this point needs convincing how utterly disgusting incompetent they’re at software.

      • gedy an hour ago ago

        They reduced the radius back to older, smaller size and now all apps use a single radius, vs the weird 3 different radii in Tahoe. Looks better.

        • hbn an hour ago ago

          I was shocked to find out the inconsistent corner radii in Tahoe was an intentional design decision. I figured it's so obviously bad that it was just sloppy work. But one of the WWDC session videos bafflingly clarified that it depends on whether the app has a toolbar or not.

          https://youtu.be/VqTn9NgiE1s?t=439

          I can't imagine how the people who signed off on that were put in charge of design at Apple.

  • embedding-shape 5 hours ago ago

    Lots of "in collaboration with Claude and Anthropic Research" mentions, no mentions of other labs. I'd assume Apple already had access to whatever the most powerful model is at the various US-based labs, but perhaps not?

    • woadwarrior01 3 hours ago ago

      Those were voluntary disclosures by two Anthropic researchers and the security firm Calif. I know one more CVE on the list that was discovered using an AI agent and wasn't disclosed as such. I suspect there are many more.

    • tombot 5 hours ago ago

      Apple isn’t friends with OpenAI anymore

    • lapcat 3 hours ago ago

      > Lots of "in collaboration with Claude and Anthropic Research" mentions

      I wouldn't say 4 is lots. The entire list is massive. I haven't counted myself, but someone claimed that macOS 26.6 has the all-time record with 155 CVEs.

    • claiir 39 minutes ago ago

      also “ Using GLM From Z.AI”

    • senadir 4 hours ago ago

      Apple also hosts a copy of Claude internally in their servers.

      • cromka 4 hours ago ago

        Do they? As in Claude but on premises? Wonder if this is gonna be the solution that e.g. banks will require, exactly like they do now for cloud services (e.g. Azure on premises).

        • Cider9986 3 hours ago ago

          Banks are all about security theatre so probably not.

        • pbronez 4 hours ago ago

          Pretty extreme solution… you can get Claude models from AWS Bedrock and Google Model Zoo. These are both very helpful for compliance and security, but do require you to have a cloud strategy.

          • ainch 3 hours ago ago

            Some data is so sensitive it likely has to stay on premises though.

          • UqWBcuFx6NV4r 3 hours ago ago

            Yeah, albeit an increasingly second-rate experience, at least when it comes to Bedrock.

      • bel8 2 hours ago ago

        source?

        • mholm 2 hours ago ago

          I don't believe it's published anywhere, but it's common knowledge to Apple engineers. I can second the poster's assertion that they run Claude internally.

          • MBCook 2 hours ago ago

            I know they use it, they host it too?

            That would be a very Apple thing to do.

        • MBCook 2 hours ago ago

          I don’t know about hosting it internally but a an Apple focused podcast I listen to (Accidental Tech Podcast) has mentioned numerous times in the last few months they’re using Claude heavily. And they know Apple insiders.

  • pjmlp 4 hours ago ago

    Map the amount of fixes with "... improved bounds checking...", "...improved memory handling...", "...improved memory management..." into the amount of developer, QA and release management teams salaries per hour, versus other stuff they could be working on, and that gives an approximate value of how using specific languages maps into monetary loss, and why companies are starting to care nowadays, given computers are always exposed to the world network.

    • snvzz 3 hours ago ago

      If anything, there's a strong argument to switch to seL4.

      • Groxx a minute ago ago

        [delayed]

    • bluecalm 4 hours ago ago

      >>, and that gives an approximate value of how using specific languages maps into monetary loss, and why companies are starting to care nowadays, given computers are always exposed to the world network.

      You need also factor development time and ease of finding developers willing to work in a specific language. There are other factors like readability of the code (very verbose languages are likely to be worse) and cost of maintenance - languages forcing a lot of abstractions are likely much worse.

      • acdha 3 hours ago ago

        > You need also factor development time and ease of finding developers willing to work in a specific language

        This even more strongly favors Rust or Swift. Nobody is writing C or even Objective-C in 2026 as a growth language.

        • zbentley 2 hours ago ago

          If you just meant apple-targeting developers, then yeah; you're right that those languages are in decline. But if you meant developers in general, I think you'd be surprised how many growth sectors are hiring C programmers. They're often not SaaS tech companies, but they are massive and many are growing. Hardware, industrial control systems, defense/aerospace ... there's a ton there, the spaces in which they hire just don't overlap a ton with the spaces frequented by hacker news. Also, a lot of them aren't US based companies.

          I hope that changes over time, since I definitely agree that the downsides of C-family languages massively outweigh the downsides of competitor languages.

          • pjmlp 33 minutes ago ago

            Which is why WG14 and WG21 caring about security would be quite relevant, but alas, priorities.

            C could have gotten slices already in the 90's, the concept already existed in other languages, and even Dennis Ritchie made a fat pointer proposal into that sense.

            The others, let see if anything related to profiles actually gets into C++29.

      • zbentley 2 hours ago ago

        > very verbose languages are likely to be worse

        Citation needed. I don't think there's a correlation there. Over-architected Java spaghetti is verbose and unmaintainable. Under-architected Perl code golf that metastisized is terse and unmaintainable.

        > languages forcing a lot of abstractions are likely much worse

        Citation needed. C++ has had some very high-level abstractions on top of a low-level runtime for awhile, and plenty of people have decided to use it and hire for it regardless. What counts as an "abstraction" or "forced abstraction" is a very very subjective topic.

        • pjmlp 30 minutes ago ago

          Even C can be super abstracted, see early 1980-90's business software written in C, with nice stuff like Yourdon Structured Method, leading to over-architected C spaghetti with macros, a decade before Java came to be.

          The problem is the lack of interest since Morris worm came to be, to provide better mechanisms in said languages, until governments and key big tech names decided it was time to change existing practices.

    • UqWBcuFx6NV4r 3 hours ago ago

      “nah bro, all those other developers are just garbage, I am the one person that can write memory safe C”

  • AJRF 5 hours ago ago

    Weird thing to see at number 3 on HN - is there some subtle context I am missing here?

    Are we wink winking that it's a lot of fixes?

    • microtonal 3 hours ago ago

      It is a lot of fixes and the Android Security Bulletins of June and Android 17 also had a lot of fixes [1], despite ASBs only containing high/critical vulnerabilities (other vulnerabilities are only fixed in major releases and QPRs, which most Android vendors respectively roll out late or never at all).

      I think the story here is that vulnerability discovery has accelerated a lot with LLMs, but since are adversaries are doing the same, it is more important than ever to update quickly (and not let some Android vendors get away with their lazy update schedules).

      [1] https://source.android.com/docs/security/bulletin/2026/2026-... https://source.android.com/docs/security/bulletin/android-17

      • cubefox 3 hours ago ago

        So using newish phones that don't get updated anymore could be a lot more dangerous now than it was just a year ago.

        • acdha 3 hours ago ago

          Right - it was always dangerous but people who figured they weren’t important enough to be attacked might find out that LLMs have shifted that cost in the wrong direction.

    • DStiego 5 hours ago ago

      Relevant context might be for example that there are 4 mentions each of Claude by Anthropic and XGPT by ThreatBook, both based on LLMs.

      AI attribution might be one reason people are particularly curious.

      • AJRF 3 hours ago ago

        I missed that, thanks for pointing out

    • grahamlee 5 hours ago ago

      And it's not actually that much information "about the security content". For example: "Impact: An app may be able to access sensitive user data. Description: An access issue was addressed with additional sandbox restrictions." This references CVE-2026-43819, which doesn't have any more information. Compare this with the nearly decade-old https://support.apple.com/en-gb/103680, and you see much more specific information about problems and their remedies (except in situations where Apple's action was to update a vendor component).

      • Gigachad an hour ago ago

        The vagueness could be intentional. There’s been a big issue with linux where proof of concept exploit code gets posted before the bug is announced because people reverse engineer it from the fix commits.

        Apple has the advantage that they can keep everything secret for long enough for the patches to roll out. And realistically there is no reason the user needs to know the details of an exploit that was patched before it was ever used.

    • Tepix 4 hours ago ago
    • cromka 4 hours ago ago

      I think it's because it's the first big batch of fixes found at Apple by Mythos.

      • nozzlegear an hour ago ago

        Is this speculation? Where does it say Mythos was responsible for any of this?

    • croemer 5 hours ago ago

      I think that's it?

  • nizbit 5 hours ago ago

    Collision counts are absurd. CVE-2026-43739 has roughly twenty credited researchers; CVE-2026-43816 has nearly as many. And ai attribution getting credit.

    • croemer 5 hours ago ago

      One CVE even lists the same person twice!

      CVE-2026-64691: Ruslan Dautov, Ruslan Dautov