Official source evidencesupport.apple.comVersioned article
Official source article · support.apple.com

About the security content of macOS Tahoe 26.5 - Apple Support

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2025-14819OpenSSL partial chain store policy bypass
  • CVE-2025-14017broken TLS options for threaded LDAPS
  • CVE-2026-43661A buffer overflow issue was addressed with improved memory handling
  • CVE-2026-28969A use after free issue was addressed with improved memory management
  • CVE-2026-43670A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts
  • CVE-2026-28900A file quarantine bypass was addressed with additional checks
  • CVE-2026-28849A maliciously crafted ZIP archive may bypass Gatekeeper checks
  • CVE-2026-28984The issue was addressed with improved memory handling
  • CVE-2026-39877A memory corruption issue was addressed with improved memory handling
  • CVE-2026-43667An attacker in a privileged network position may be able to cause a denial-of-service
  • CVE-2026-28995A logic issue was addressed with improved restrictions
  • CVE-2026-43658The issue was addressed with improved memory handling
  • CVE-2026-28947A use-after-free issue was addressed with improved memory management
  • CVE-2026-28990The issue was addressed with improved memory handling
  • CVE-2026-28958This issue was addressed with improved data protection
  • CVE-2026-28996A race condition was addressed with additional validation
  • CVE-2026-43653An attacker on the local network may be able to cause a denial-of-service
  • CVE-2026-28983A remote attacker may be able to cause a denial of service
  • CVE-2026-28936The issue was addressed with improved checks
  • CVE-2026-28961An attacker with physical access to a locked device may be able to view sensitive user information
  • CVE-2026-28914A maliciously crafted ZIP archive may bypass Gatekeeper checks
  • CVE-2026-1837libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2
  • CVE-2026-28847The issue was addressed with improved memory handling
  • CVE-2026-28883A use-after-free issue was addressed with improved memory management
  • CVE-2026-28901The issue was addressed with improved memory handling
  • CVE-2026-28902The issue was addressed with improved memory handling
  • CVE-2026-28903The issue was addressed with improved memory handling
  • CVE-2026-28904The issue was addressed with improved memory handling
  • CVE-2026-28905The issue was addressed with improved memory handling
  • CVE-2026-28942A use-after-free issue was addressed with improved memory management
  • CVE-2026-28946A use-after-free issue was addressed with improved memory management
  • CVE-2026-28953The issue was addressed with improved memory handling
  • CVE-2026-28955The issue was addressed with improved memory handling
  • CVE-2026-28940The issue was addressed with improved memory handling
  • CVE-2026-43654The issue was addressed with improved memory handling
  • CVE-2026-28917The issue was addressed with improved input validation
  • CVE-2026-28907The issue was addressed with improved input validation
  • CVE-2026-28971The issue was addressed with improved UI handling
  • CVE-2026-28913The issue was addressed with improved memory handling
  • CVE-2026-28944The issue was addressed with improved memory handling
  • CVE-2026-43660A validation issue was addressed with improved logic
  • CVE-2026-28962This issue was addressed with improved access restrictions
  • CVE-2026-28943A logging issue was addressed with improved data redaction
  • CVE-2026-28915A parsing issue in the handling of directory paths was addressed with improved path validation
  • CVE-2026-28930A permissions issue was addressed with additional restrictions
  • CVE-2026-28920An information leakage was addressed with additional validation
  • CVE-2026-28977The issue was addressed with improved bounds checks
  • CVE-2026-43652A permissions issue was addressed with additional restrictions
  • CVE-2026-28978A permissions issue was addressed with additional restrictions
  • CVE-2026-28923A logging issue was addressed with improved data redaction

Source and provenance

Original title: About the security content of macOS Tahoe 26.5 - Apple Support. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗