About the security content of macOS Tahoe 26.6
Posted by andor 6 days ago
Comments
Comment by tengwar2 6 days ago
For context, there have been issues with MacOS 26 which have led many people to defer upgrading until MacOS 27 is available, and MacOS 15 is the previous version.
Comment by jghn 6 days ago
For me the issue is liquid glass. Which I doubt is getting fixed any time soon
Comment by illithid0 6 days ago
https://www.cultofmac.com/news/liquid-glass-changes-ios-27-m...
Comment by hbn 6 days ago
Comment by noname120 6 days ago
Comment by classified 6 days ago
Comment by noname120 5 days ago
Comment by iknowstuff 6 days ago
Comment by lapcat 6 days ago
Having installed the beta, I think that's the best you can say about it.
Comment by etempleton 6 days ago
Comment by lapcat 6 days ago
Nothing will ever be as good as 25.
Because macOS 25 does not exist. ;-)
Comment by etempleton 6 days ago
Comment by Jolter 6 days ago
Comment by illithid0 6 days ago
Comment by ChrisMarshallNY 6 days ago
iOS 26 anecdote:
A couple of weeks ago, I had a Baltimore Oriole (a cool-looking bird, not a baseball player) in my yard. They aren't rare, per se, but they are uncommon.
Took my iPhone out to snap a picture, and pressed the camera button. I hadn't used it, since upgrading to 26.
It takes the picture. It's there. I can see it, but it won't let me save it. Instead, it wants to tell me about the cool new voice-activated AI retouch feature. There was no way to save.
I probably could have figured it out, but I was so furious, I just nuked the picture.
Comment by DHPersonal 5 days ago
Comment by ChrisMarshallNY 3 days ago
Comment by pseudosaid 5 days ago
Comment by ChrisMarshallNY 3 days ago
Fairly typical kind of workflow, that most apps do, these days. It’s just that the timing couldn’t have been worse.
> You must be a bot, just another living shill. another confident user error in the field
I have no idea what that means.
Comment by dylan604 6 days ago
For those of us older than just 10 years of using macOS, the older Apple OSes have instilled within us the desire to never install the X.0 release and wait until at least the X.1 release. The bug-free experience is a myth
Comment by D-Coder 5 days ago
I think that applies to almost all software, not just Apple OSes. After all, Confucius said: "The only thing worse than old software is new software."
Comment by trollbridge 6 days ago
Comment by flohofwoe 6 days ago
I had that turned off years ago (for reasons I don't remember), and was wondering what all the fuzz was about when 26 came out because I didn't see much of a difference ;)
IMHO the actual important visual changes in the 27 beta is that rolls back the bizarre oversized corner radius in Finder windows, and they also got rid of the 'every menu item must have an icon' idea.
Comment by trollbridge 6 days ago
Comment by SanjayMehta 6 days ago
Comment by trollbridge 5 days ago
Comment by Hamuko 6 days ago
I might update to macOS 26 in September to be ready to update to macOS 27. Being two versions behind doesn't seem reasonable and I'd rather be on the "Tahoe but less shitty" version than Tahoe itself.
Comment by coldpie 6 days ago
Comment by Melatonic 5 days ago
Comment by pmdr 6 days ago
Seriously, who the heck even asked for those?
Comment by IdiotSavage 6 days ago
Comment by hbn 6 days ago
https://www.macrumors.com/2026/06/09/macos-golden-gate-liqui...
Comment by ak217 6 days ago
Comment by frizlab 6 days ago
Comment by reddalo 6 days ago
Comment by coatmatter 5 days ago
I recently made the move away from an out-of-support macOS 12 Monterey to Debian Stable (13 trixie), after some failed attempts to upgrade macOS using OpenCore Legacy Patcher.
While Linux support will always remain far from perfect with that series of MBP, it was still much better than I expected compared to my last look many years ago. I happen to get better use out of my particular setup now compared to macOS; as it's basically a glorified streaming device that I interact with through wayvnc/vncviewer out of arm's reach across a table. This also allows me to mostly avoid using the semi-busted Butterfly keyboard.
In addition to having something with security updates again, I'll now never need to think about Apple dropping Intel support. I'd also like to note that nix-darwin support on Intel macOS is ending very soon too - but not Linux + nix as a package manager (nixpkgs) since that combination is separate to macOS + nix-darwin.
Comment by drnick1 6 days ago
Comment by normie3000 5 days ago
Comment by cyberax 5 days ago
Comment by normie3000 4 days ago
Comment by shepherdjerred 6 days ago
Comment by simlevesque 6 days ago
Comment by embedding-shape 6 days ago
Comment by GeekyBear 5 days ago
Comment by pjmlp 5 days ago
Comment by GeekyBear 5 days ago
However, Software Update on Apple devices still allows you to turn off automatic update installation the way Windows used to.
Comment by pjmlp 5 days ago
For quite some time that I don't use home edition.
I also would not bet on Apple staying that way.
Comment by GeekyBear 4 days ago
It's right up there with Microsoft's "you are not allowed to turn telemetry all the way off", or all the efforts to require the use of an online Microsoft account to access your own computer.
Comment by pjmlp 4 days ago
Ever heard of Local Group Policy Editor?
Comment by GeekyBear 4 days ago
Secure Boot initially didn't allow the install of operating systems other than Windows.
Microsoft is the company continually attempting to lock down their general purpose computers, not Apple.
...and no. Microsoft backing down aftet consumers revolt doesn't mean their attempts don't count.
Comment by pjmlp 3 days ago
Comment by DavideNL 6 days ago
Comment by embedding-shape 6 days ago
Yeah, I thought so too, but surprise surprise; some months ago one of the "minor" updates "broke" ("upgraded") something that made my CI/CD setup stop working, that's when I dropped the idea that Apple even do "minor" updates anymore.
Comment by bouke 6 days ago
Comment by reddalo 6 days ago
Then there's me, crying in MacBook Pro 2019 stuck on MacOS 15 because 27 won't be available for my machine.
Comment by ExoticPearTree 6 days ago
Comment by andreasley 6 days ago
Comment by carra 6 days ago
Comment by kylemaxwell 6 days ago
Comment by hbn 6 days ago
macOS went from 15 to 26
iOS went from 18 to 26
watchOS went from 11 to 26
and so on
Comment by classified 6 days ago
Comment by gokohl 6 days ago
Comment by crossroadsguy 6 days ago
Comment by gedy 6 days ago
Comment by hbn 6 days ago
https://youtu.be/VqTn9NgiE1s?t=439
I can't imagine how the people who signed off on that were put in charge of design at Apple.
Comment by gedy 6 days ago
Then the reality of "what about toolbars", "what about dark mode", "what about laptop screens", etc were all afterthoughts and resulted in bolt-on fixes like that.
Comment by pjmlp 6 days ago
Comment by bluecalm 6 days ago
You need also factor development time and ease of finding developers willing to work in a specific language. There are other factors like readability of the code (very verbose languages are likely to be worse) and cost of maintenance - languages forcing a lot of abstractions are likely much worse.
Comment by acdha 6 days ago
This even more strongly favors Rust or Swift. Nobody is writing C or even Objective-C in 2026 as a growth language.
Comment by zbentley 6 days ago
I hope that changes over time, since I definitely agree that the downsides of C-family languages massively outweigh the downsides of competitor languages.
Comment by pjmlp 6 days ago
C could have gotten slices already in the 90's, the concept already existed in other languages, and even Dennis Ritchie made a fat pointer proposal into that sense.
The others, let see if anything related to profiles actually gets into C++29.
Comment by acdha 6 days ago
Comment by zbentley 6 days ago
Citation needed. I don't think there's a correlation there. Over-architected Java spaghetti is verbose and unmaintainable. Under-architected Perl code golf that metastisized is terse and unmaintainable.
> languages forcing a lot of abstractions are likely much worse
Citation needed. C++ has had some very high-level abstractions on top of a low-level runtime for awhile, and plenty of people have decided to use it and hire for it regardless. What counts as an "abstraction" or "forced abstraction" is a very very subjective topic.
Comment by pjmlp 6 days ago
The problem is the lack of interest since Morris worm came to be, to provide better mechanisms in said languages, until governments and key big tech names decided it was time to change existing practices.
Comment by snvzz 6 days ago
Comment by yjftsjthsd-h 6 days ago
Comment by pjmlp 6 days ago
Comment by UqWBcuFx6NV4r 6 days ago
Comment by embedding-shape 6 days ago
Comment by woadwarrior01 6 days ago
Comment by tombot 6 days ago
Comment by muterad_murilax 6 days ago
Comment by fnord123 6 days ago
Comment by mrtksn 6 days ago
Allegedly of course.
Comment by makeitdouble 6 days ago
Jony Ive basically works for Open AI (it's more complicated, but it's a good approximation), and has more or less rebuilt a designing team over there.
He's not the central person mentioned in Apple's accusations but that's arguably the central point that's triggering all of this.
Comment by ajmurmann 6 days ago
Comment by danso 6 days ago
Comment by alwillis 6 days ago
He "took" several Apple employees with him when he left and there's been a steady stream of Apple employees going to OpenAI.
Ive isn’t responsible for all of them obviously, but the articles about lawsuits says there are 400 former Apple employees at OpenAI.
Comment by SoftTalker 6 days ago
Comment by acdha 5 days ago
Without his support, his protege Alan Dye left for Meta and improved the design skills at both companies.
Comment by manmal 5 days ago
Comment by MBCook 6 days ago
Comment by anonymars 6 days ago
Comment by lapcat 6 days ago
I wouldn't say 4 is lots. The entire list is massive. I haven't counted myself, but someone claimed that macOS 26.6 has the all-time record with 155 CVEs.
Comment by embedding-shape 6 days ago
Comment by senadir 6 days ago
Comment by cromka 6 days ago
Comment by Cider9986 6 days ago
Comment by pbronez 6 days ago
Comment by ainch 6 days ago
Comment by cromka 6 days ago
Comment by UqWBcuFx6NV4r 6 days ago
Comment by bel8 6 days ago
edit: it seems asking for a source it frowned uppon in this site. And it seems there's no source.
Comment by mholm 6 days ago
Comment by MBCook 6 days ago
That would be a very Apple thing to do.
Comment by bel8 6 days ago
And it seems nobody has a source so it's just humors as usual.
Comment by mholm 6 days ago
Comment by MBCook 6 days ago
Comment by alwillis 6 days ago
That's something Steve Jobs would have done.
Comment by MBCook 6 days ago
Comment by claiir 6 days ago
Comment by AJRF 6 days ago
Are we wink winking that it's a lot of fixes?
Comment by microtonal 6 days ago
I think the story here is that vulnerability discovery has accelerated a lot with LLMs, but since are adversaries are doing the same, it is more important than ever to update quickly (and not let some Android vendors get away with their lazy update schedules).
[1] https://source.android.com/docs/security/bulletin/2026/2026-... https://source.android.com/docs/security/bulletin/android-17
Comment by cubefox 6 days ago
Comment by grahamlee 6 days ago
Comment by Gigachad 6 days ago
Apple has the advantage that they can keep everything secret for long enough for the patches to roll out. And realistically there is no reason the user needs to know the details of an exploit that was patched before it was ever used.
Comment by eviks 5 days ago
But since this is never known, does the user need to know?
Comment by acdha 5 days ago
Comment by DStiego 6 days ago
AI attribution might be one reason people are particularly curious.
Comment by AJRF 6 days ago
Comment by cromka 6 days ago
Comment by nozzlegear 6 days ago
Comment by cromka 6 days ago
Comment by Tepix 6 days ago
Comment by croemer 6 days ago
Comment by TheJoeMan 6 days ago
I do not see a "typical" user needing to access a path with say a network storage but multiple ../.. and hard and soft symlinks simultaneously. I think "be liberal in what you accept" might need to be revisited for path parsing with some sort of OS-wide single-implementation as an optional feature.
Comment by acuozzo 6 days ago
Typical users run software written by atypical users.
> some sort of OS-wide single-implementation
How do you propose handling migration? What if someone tries to expand an old archive file containing a now-forbidden path?
Comment by TheJoeMan 6 days ago
Comment by SoftTalker 6 days ago
If there's a path on the system that the user should not be able to read, that's the job of the OS to handle, not the individual applications.
Comment by eviks 5 days ago
Comment by catlifeonmars 6 days ago
Comment by nizbit 6 days ago
Comment by croemer 6 days ago
CVE-2026-64691: Ruslan Dautov, Ruslan Dautov
Comment by Someone 6 days ago
Not necessarily. Could be two persons sharing that name. See https://revstat.ine.pt/index.php/REVSTAT/article/view/382
Comment by ayewo 5 days ago
Comment by proactivesvcs 6 days ago
CVE-2026-43744: Mathis Mansière, an anonymous researcher
Comment by nkrisc 6 days ago
Comment by rubslopes 6 days ago
Comment by darkwater 6 days ago
Comment by receiptful-io 6 days ago
Comment by conradfr 6 days ago
Comment by FabHK 6 days ago
Comment by BoardsOfCanada 6 days ago