• Sources: Apple support 128067, HN 49081555
  • Summary: Apple's security-content page for macOS Tahoe 26.6 resolved with its CVE table on this run, after returning page chrome only on previous runs. The entries read name CVEs and credited researchers for several root-privilege escalations and for memory-corruption paths in the kernel, HFS, Disk Images, ImageIO, and CoreAudio. The fetch truncated at 20,000 characters partway through the CVE list, so no total CVE count is stated here and no claim about active exploitation is made, because neither could be read.
  • Why it matters: Named CVEs with the affected component are what a fleet operator needs to rank the update against its own exposure.
  • Follow-up: Read the full CVE table on a later fetch, and check whether Apple marks any entry as exploited.

send feedback on this story