macOS Tahoe Release History
Comprehensive changelog, security updates, and enterprise deployment notes for the macOS 26 lifecycle. Information curated for IT administrators and power users.
Overview: Major security patch release for macOS Tahoe resolving nearly 30 security vulnerabilities across system components including Kernel, WebKit, Audio, ImageIO, and IOGPUFamily. Recommended for immediate installation by all users and Mac admins.
- Kernel & System Vulnerabilities: Improved input sanitization and bounds checking to prevent arbitrary code execution with kernel privileges.
- Graphics & Media (IOGPUFamily & ImageIO): Addressed race conditions and memory corruption vulnerabilities when processing malicious media content.
- WebKit Engine: Patched zero-day memory handling flaws aligned with iOS 26.6.1 fixes.
Overview: Emergency security release for macOS Tahoe addressing a zero-day vulnerability in Screen Sharing (CVE-2026-65400). Available via Software Update, standalone InstallAssistant.pkg, and IPSW restore image for Apple Silicon.
- Screen Sharing (CVE-2026-65400): Addressed with improved state management to prevent an unauthenticated attacker on the same network from gaining access to Screen Sharing.
- System Security & Stability: Supplemental fixes focused on critical remote authentication security.
Overview: Official stable release of macOS Tahoe 26.6 containing cumulative security patches, Safari 26.6 enhancements, stability fixes, and enterprise management improvements. Available via Software Update, full InstallAssistant.pkg, and IPSW restore image for Apple Silicon.
- Safari 26.6: Performance optimizations, WebKit security improvements, and enhanced tab management.
- Security & Stability: Critical patches across system kernel, graphics drivers, and system services.
- Enterprise Administration: MDM profile enhancements and seamless software deployment updates.
Overview: A security-focused update addressing approximately 29 vulnerabilities across the Kernel, WebKit, IOGPUFamily, and libxslt. Fixes were backported from the ongoing macOS 26.6 beta cycle. Recommended for all users immediately.
- IOGPUFamily (CVE-2026-43743): A race condition was addressed with improved state handling, preventing an app from causing unexpected system termination.
- Kernel (CVE-2026-43724): Addressed with improved input sanitization; an app could previously cause unexpected system termination or write to kernel memory.
- Kernel (CVE-2026-43722): Addressed with improved input sanitization, preventing an app from leaking sensitive kernel state.
- Kernel (CVE-2026-39868): Addressed with improved input validation, preventing an app from causing unexpected system termination or corrupting kernel memory.
- libxslt (CVE-2026-43706): A double-free issue was fixed with improved memory management, preventing malicious web content from causing an unexpected process crash.
- WebKit: 19 WebKit vulnerability fixes addressing issues including arbitrary code execution, CSP bypass, and use-after-free crashes.
Overview: A major update delivering security patches, a significant Safari update (security content published May 13), and stability improvements. Superseded by macOS 26.5.2.
- 14 WebKit CVEs: All security patches in this Safari update target WebKit (and one WebRTC). Impacts include: CSP enforcement bypass, sensitive user data disclosure, process crashes via use-after-free, and malicious iframe download-settings abuse. (CVE-2026-43660, 28907, 28962, 43658, 28905, 28847, 28904, 28955, 28903, 28953, 28902, 28901, 28913, 28883, 28958, 28917, 28947, 28946, 28942, 28971)
- Available for: macOS Sonoma and macOS Sequoia (standalone Safari update for older macOS). Safari on iOS 26.5, iPadOS 26.5, and visionOS 26.5 is included with those OS updates.
- 63 Bug Fixes: Improvements to Scroll-driven animations, Anchor Positioning, WebRTC, networking, and rendering at different zoom levels.
- CSS
:openPseudo-class: Consistent styling for the open state of<details>,<dialog>,<select>, and<input>elements. - CSS
random()Updates:element-scopedkeyword for per-element randomness; caching updated to global-by-default per spec. - SVG & Web APIs:
color-interpolationfor SVG gradients,ToggleEvent.sourcefor popovers, and the Origin API.
- System Security: Addressed multiple vulnerabilities that could lead to arbitrary code execution, including WebKit and Kernel patches.
- Stability Improvements: Resolves system instability issues and improves overall device performance.
Overview: Important security update providing crucial vulnerability patches and system enhancements recommended for all users.
- System Security: Addressed multiple vulnerabilities that could lead to arbitrary code execution (CVE fixes).
- Stability Improvements: Resolves system instability issues and improves overall device performance.
Overview: Minor update providing crucial bug fixes and enabling support for the Studio Display and Studio Display XDR.
Overview: The third major point release for macOS Tahoe focuses on window management and Safari enhancements.
- Window Management: Fixes sticky edge behavior in Stage Manager.
- Safari: Web profiles can now have distinct dock icons.
- Enterprise Config: Updates to MDM protocol for declarative device management.
Overview: Stability and performance focus for the winter cycle.
- Gaming Mode: Enhanced performance priority for game porting toolkit compatibility.
- Finder: "Smart Folders" now support regex-based filtering.
- Freeform: Infinite canvas performance improvements for large boards.
Overview: A stability-focused release addressing early bugs from the initial 26.0 launch.
Overview: The massive annual update bringing major new features and ecosystem enhancements.