NCSC-2026-0267 [1.00] [M/H] Vulnerabilities fixed in Apple MacOS
Apple has fixed multiple vulnerabilities in MacOS, specifically in versions Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.x. The vulnerabilities involve various security issues in macOS, including insufficient sandbox restrictions that may allow applications unauthorized access to sensitive user data. Issues related to improper memory handling, such as use-after-free, buffer overflows, out-of-bounds reads and writes, integer overflows, race conditions, and type confusion have been resolved. These can lead to unexpected system or application terminations, privilege escalation, unauthorized access to kernel memory, and in some cases remote code execution. Additionally, there are fixes for bypasses of Gatekeeper security via manipulated ZIP archives, improved validation of file and path processing, and strengthened authorization and permission controls. Improvements have also been made in network security, such as preventing interception of network connections and limiting application permissions. The updates focus on strengthening memory management, input validation, state management, and sandbox isolation to prevent unauthorized access and system instability. The vulnerabilities have been resolved in the mentioned macOS versions, and some fixes have also been implemented in related Apple operating systems such as iOS, iPadOS, tvOS, visionOS, and watchOS.
CSIRTS triage
- What
- Multiple vulnerabilities in macOS can lead to unauthorized access to sensitive user data, privilege escalation, and in some cases remote code execution.
- Who is affected
- Users of the specified versions of macOS are affected.
- Urgency
- Remediation is high urgency due to the severity of the vulnerabilities and potential for exploitation.
- Action
- Update to the latest version of macOS to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch macOS
Get an email when a new macOS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0267
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-433250.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-37830.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-37840.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-44240.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all scored CVEs.
- Low exploitation riskCVE-2026-206720.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Elevated exploitation riskCVE-2026-2391849.7% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 99% of all scored CVEs.
- Low exploitation riskCVE-2026-288490.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-288960.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-289000.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-289110.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple Safari: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple iOS and iPadOS: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0266 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOSncsc-nl
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Apple products (July 28, 2026)cert-fr-avis
- mediumCVE-2026-43754: This issue was addressed with improved redaction of sensitive information. This issue is fixed…nvd
- mediumCVE-2026-43753: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS …nvd
Recent advisories for Apple MacOS
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund · 2026-07-28
- critical[UPDATE] [critical] Apple macOS: Multiple Vulnerabilitiescert-bund · 2026-07-15
- high[UPDATE] [high] Apple macOS Sequoia, Sonoma, and Ventura: Multiple Vulnerabilitiescert-bund · 2026-07-15
- high[UPDATE] [high] Apple macOS: Multiple vulnerabilitiescert-bund · 2026-07-15
- unknownNCSC-2026-0214 [1.00] [M/H] Vulnerabilities fixed in Apple MacOSncsc-nl · 2026-06-30
- criticalexploitedCVE-2025-43300: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerabilitycisa-kev · 2025-08-21
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30