Header Banner
Gadget Hacks Logo
Gadget Hacks
Apple
gadgethacks.mark.png
Gadget Hacks Shop Apple Guides Android Guides iPhone Guides Mac Guides Pixel Guides Samsung Guides Tweaks & Hacks Privacy & Security Productivity Hacks Movies & TV Smartphone Gaming Music & Audio Travel Tips Videography Tips Chat Apps
Home
Apple

macOS Tahoe 26.6.1 Security Fixes: No Advisory Published

"macOS Tahoe 26.6.1 Security Fixes: No Advisory Published" cover image

Apple released macOS Tahoe 26.6.1 on August 6, 2026, with a security advisory covering one Screen Sharing vulnerability. Apple identifies the flaw as CVE-2026-65400 and says an attacker on the network may be able to authenticate to Screen Sharing without valid credentials. The company addressed the authentication issue with improved state management.

The update follows macOS Tahoe 26.6, released July 27, which carried a much larger batch of security fixes. SecurityWeek counted 155 vulnerabilities addressed in that release; TidBITS counted 143.

SecurityWeek counted 155 vulnerability fixes in that release; TidBITS put the figure at 143. Either way, the July cycle addressed sensitive-data exposure, arbitrary code execution, security bypasses, and denial-of-service issues in macOS Tahoe. Two of those fixes, covering how Macs handle images and hidden file metadata, say more about what's actually at stake for everyday users than either count does on its own.

What follows covers where 26.6.1 currently stands, the file-handling risk carried over from 26.6, and what the gap in Apple's advisory means for Macs running Tahoe, Sequoia, or Sonoma.

macOS Tahoe 26.6.1 security fixes: what Apple has confirmed

Apple has documented one security fix in macOS Tahoe 26.6.1. The August 6 advisory identifies CVE-2026-65400 in Screen Sharing and says an attacker on the network may be able to authenticate without valid credentials. Apple says it addressed the authentication issue with improved state management.

That makes 26.6.1 the latest documented Tahoe security update. It does not replace the much broader security record of 26.6; instead, it adds a newly documented Screen Sharing fix on top of that July release.

The file-parsing risk that still matters most to everyday users

Two fixes from the 26.6 cycle explain the everyday risk better than any CVE count. The first involves ImageIO, the system framework that decodes JPEG, PNG, TIFF, RAW, and GIF files, used constantly by Photos, Safari, Messages, Mail, and Preview. Apple's fix, tracked as CVE-2026-43818, addresses a flaw triggered when a Mac processes a maliciously crafted image.

Because ImageIO sits underneath so many ordinary apps, an image arriving through a text thread, an email, or a shared album can exercise the same vulnerable code path without anyone doing anything unusual.

The second fix targets AppleDouble, the code macOS uses behind the scenes to store hidden file metadata like icons and Finder details on certain disks and servers. Malwarebytes notes this code becomes relevant specifically when files sit on network drives or move between Apple and non-Apple systems, which makes CVE-2026-43776 a narrower risk than the ImageIO flaw. The issue barely registers for someone who never uses network shares or crosses between a Mac and a Windows machine. It matters a great deal to someone who does that daily.

Both fixes carry Apple's standard advisory language for memory-corruption bugs in file parsers: processing a maliciously crafted file "may lead to unexpected app termination or arbitrary code execution." Malwarebytes describes that wording as covering a range: a crash in the ordinary case, an attacker running code on the device in the worst one. Treating it as a guaranteed takeover overstates the claim; treating it as nothing worth worrying about understates it just as badly.

What this means for Tahoe, Sequoia, and Sonoma users

Anyone running Tahoe who hasn't installed 26.6 yet still needs the large set of July security fixes, including the ImageIO and AppleDouble flaws described above. But 26.6 is no longer the newest documented security release: Apple followed it with macOS Tahoe 26.6.1 on August 6 to address CVE-2026-65400 in Screen Sharing.

Macs already running 26.6 should therefore check Software Update for 26.6.1 rather than assume the July build is fully current.

Apple issued parallel updates for its two older supported macOS generations as well. macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9 were released August 6 with the same Screen Sharing fix, so users on those systems should check for those builds rather than the July releases, Sequoia 15.7.8 and Sonoma 14.8.8.

How to check your version and install the right update

None of the vulnerabilities patched in the July cycle are known to be actively exploited, according to both MacRumors and TidBITS. MacRumors warned that unpatched devices could be vulnerable once the issues became public knowledge, even without evidence of active exploitation.

Malwarebytes and TidBITS land in different places on urgency. Malwarebytes recommended installing the July updates as soon as possible, given how many touched core file-handling frameworks. TidBITS took a more measured view: since Apple hadn't flagged any of the flaws as exploited, users could reasonably wait a few days after release to watch for compatibility issues, such as the incorrect Intel-app warning Apple fixed in that same cycle.

Checking version status is straightforward: open System Settings > General > Software Update, note the installed macOS version and build number, and install whatever Apple currently offers there. Apple's security-updates page is the place to confirm that what's installed matches what's currently documented, instead of relying on a version number remembered from a few weeks back.

What to watch for next

Apple has not documented macOS Tahoe 26.6.1 as a security release. Until it does, 26.6 is the record of what's actually been fixed on Tahoe, and this article can't responsibly assign 26.6.1 a CVE list or claim it extends protection Apple hasn't described.

If 26.6.1 does eventually arrive with its own advisory, the habit that matters is checking Apple's security-updates page against whatever build a Mac is running, not tracking a single version number and assuming it inherited the last one's fixes.

Apple's iOS 26 and iPadOS 26 updates are packed with new features, and you can try them before almost everyone else. First, check our list of supported iPhone and iPad models, then follow our step-by-step guide to install the iOS/iPadOS 26 beta — no paid developer account required.

Sponsored

Related Articles

Comments

No Comments Exist

Be the first, drop a comment!