As cited
Copy frozen at (site build).
vulnerabilities
The Apple macOS Security Update Review
Apple released 82 unique CVEs in May 2026 across three macOS versions: 79 for Tahoe 26.5, 45 for Sequoia 15.7.7, and 42 for Sonoma 14.8.7. Several vulnerabilities stand out as particularly severe, including a Wi-Fi flaw (CVE-2026-28819) enabling arbitrary code execution with kernel privileges, an mDNSResponder vulnerability (CVE-2026-43668) allowing remote kernel memory corruption, and a kernel out-of-bounds write (CVE-2026-28972) affecting all supported macOS versions. The patches address issues ranging from sandbox escapes and privilege escalation to memory corruption and denial-of-service conditions.
Why it matters: macOS administrators and users should prioritize patching the three critical vulnerabilities affecting all macOS versions: kernel privilege escalation through Wi-Fi, remote kernel memory corruption via mDNSResponder, and kernel memory write vulnerabilities that could enable attack chains.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
The Apple macOS Security Update Review
Apple released 82 unique CVEs in May 2026 across three macOS versions: 79 for Tahoe 26.5, 45 for Sequoia 15.7.7, and 42 for Sonoma 14.8.7. Several vulnerabilities stand out as particularly severe, including a Wi-Fi flaw (CVE-2026-28819) enabling arbitrary code execution with kernel privileges, an mDNSResponder vulnerability (CVE-2026-43668) allowing remote kernel memory corruption, and a kernel out-of-bounds write (CVE-2026-28972) affecting all supported macOS versions. The patches address issues ranging from sandbox escapes and privilege escalation to memory corruption and denial-of-service conditions.
Why it matters: macOS administrators and users should prioritize patching the three critical vulnerabilities affecting all macOS versions: kernel privilege escalation through Wi-Fi, remote kernel memory corruption via mDNSResponder, and kernel memory write vulnerabilities that could enable attack chains.
- Source published
- First seen by Cybersecurity Tracker