Official source evidencesupport.apple.comVersioned article
Official source article · support.apple.com

About the security content of macOS Tahoe 26.4 - Apple Support

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs50

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2025-14524bearer token leak on cross-protocol redirect
  • CVE-2026-20679The issue was addressed with improved checks
  • CVE-2026-20696An authorization issue was addressed with improved state management
  • CVE-2026-28926A race condition was addressed with improved state handling
  • CVE-2026-28896An attacker may be able to cause unexpected system termination or read kernel memory
  • CVE-2026-28886A null pointer dereference was addressed with improved input validation
  • CVE-2026-28864A local attacker may gain access to user's Keychain items
  • CVE-2026-20687A use after free issue was addressed with improved memory management
  • CVE-2026-28868A logging issue was addressed with improved data redaction
  • CVE-2026-28852A stack overflow was addressed with improved input validation
  • CVE-2026-20665This issue was addressed through improved state management
  • CVE-2026-20690An out-of-bounds access issue was addressed with improved bounds checking
  • CVE-2026-28865An attacker in a privileged network position may be able to intercept network traffic
  • CVE-2026-28878A privacy issue was addressed by removing sensitive data
  • CVE-2026-20643Processing maliciously crafted web content may bypass Same Origin Policy
  • CVE-2026-28879A use-after-free issue was addressed with improved memory management
  • CVE-2026-28880A permissions issue was addressed with additional restrictions
  • CVE-2026-28876A parsing issue in the handling of directory paths was addressed with improved path validation
  • CVE-2026-28860A local attacker may be able to modify the state of the Keychain
  • CVE-2026-28861A logic issue was addressed with improved state management
  • CVE-2026-20657A buffer overflow issue was addressed with improved memory handling
  • CVE-2026-28866This issue was addressed with improved validation of symlinks
  • CVE-2026-28867This issue was addressed with improved authentication
  • CVE-2026-28871Visiting a maliciously crafted website may lead to a cross-site scripting attack
  • CVE-2026-20664The issue was addressed with improved memory handling
  • CVE-2026-28857The issue was addressed with improved memory handling
  • CVE-2026-28859The issue was addressed with improved memory handling
  • CVE-2026-28840A permissions issue was addressed with additional restrictions
  • CVE-2026-28910This issue was addressed with improved permissions checking
  • CVE-2026-28830A race condition was addressed with additional validation
  • CVE-2026-28877An authorization issue was addressed with improved state management
  • CVE-2026-28882This issue was addressed with improved checks
  • CVE-2026-28870An information leakage was addressed with additional validation
  • CVE-2026-28826A logic issue was addressed with improved restrictions
  • CVE-2026-28838A permissions issue was addressed with additional sandbox restrictions
  • CVE-2026-28833A permissions issue was addressed with additional restrictions
  • CVE-2026-20684An app may bypass Gatekeeper checks
  • CVE-2026-28825An out-of-bounds write issue was addressed with improved bounds checking
  • CVE-2026-20632A parsing issue in the handling of directory paths was addressed with improved path validation
  • CVE-2026-28844An attacker may gain access to protected parts of the file system
  • CVE-2026-20691An authorization issue was addressed with improved state management
  • CVE-2026-20701An access issue was addressed with additional sandbox restrictions
  • CVE-2026-20633This issue was addressed with improved handling of symlinks
  • CVE-2026-28829A permissions issue was addressed with additional restrictions
  • CVE-2026-28891A race condition was addressed with additional validation
  • CVE-2026-28845An authorization issue was addressed with improved state management
  • CVE-2026-28828A permissions issue was addressed by removing the vulnerable code
  • CVE-2026-28824An authorization issue was addressed with improved state management
  • CVE-2026-28832An out-of-bounds read was addressed with improved bounds checking
  • CVE-2026-28881A privacy issue was addressed by moving sensitive data

Source and provenance

Original title: About the security content of macOS Tahoe 26.4 - Apple Support. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗