Apple Releases macOS Tahoe 26.6 with Broad Security Fixes and Spotlight Updates

Apple's macOS Tahoe 26.6 update patches security flaws in CoreAudio, WebKit, and Spotlight, addressing memory corruption and data disclosure risks.

Jul 28, 2026
5 min read
Technobezz
Apple Releases macOS Tahoe 26.6 with Broad Security Fixes and Spotlight Updates

Don't Miss the Good Stuff

Get tech news that matters delivered weekly. Join 50,000+ readers.

Apple has released macOS Tahoe 26.6, a security-focused update for Macs running macOS Tahoe that landed on July 27, 2026.

Apple’s security bulletin documents the release and lists fixes across core system components. The company withholds details on issues until patches ship, and it tracks entries by CVE-ID where possible.

The update is available for macOS Tahoe.

CoreAudio fixes address memory corruption from a maliciously crafted audio file and an out-of-bounds write that could terminate a process when handling a crafted media stream. DesktopServices received additional checks so an app cannot bypass Gatekeeper via a file quarantine gap.

ImageIO and Model I/O patches harden memory handling for malicious images and 3D models that could corrupt or disclose process memory.

WebKit entries cover process-memory disclosure from crafted web content, tighter checks that stop sites from learning whether a user visited a given link, and stronger validation against iframe sandbox policy abuse. Spotlight also gains a bounds-checking fix for an out-of-bounds read that could let an app access sensitive user data.

Open-source components such as libarchive appear among the affected projects Apple patched in this build.

Kernel, sandbox, privilege-escalation, and media-parsing paths fill much of the bulletin, with impacts ranging from unexpected termination and memory disclosure to Gatekeeper and root-level risks. Mac users on Tahoe can pull the update through System Settings to apply the full security set Apple published for 26.6.

Share