About the security content of macOS Tahoe 26.6
Posted by andor 6 hours ago
Comments
Comment by tengwar2 4 hours ago
For context, there have been issues with MacOS 26 which have led many people to defer upgrading until MacOS 27 is available, and MacOS 15 is the previous version.
Comment by jghn 3 hours ago
For me the issue is liquid glass. Which I doubt is getting fixed any time soon
Comment by illithid0 3 hours ago
https://www.cultofmac.com/news/liquid-glass-changes-ios-27-m...
Comment by hbn 2 hours ago
Comment by noname120 2 hours ago
Comment by classified 1 hour ago
Comment by iknowstuff 56 minutes ago
Comment by trollbridge 3 hours ago
Comment by flohofwoe 3 hours ago
I had that turned off years ago (for reasons I don't remember), and was wondering what all the fuzz was about when 26 came out because I didn't see much of a difference ;)
IMHO the actual important visual changes in the 27 beta is that rolls back the bizarre oversized corner radius in Finder windows, and they also got rid of the 'every menu item must have an icon' idea.
Comment by trollbridge 3 hours ago
Comment by SanjayMehta 2 hours ago
Comment by lapcat 3 hours ago
Having installed the beta, I think that's the best you can say about it.
Comment by etempleton 3 hours ago
Comment by lapcat 3 hours ago
Nothing will ever be as good as 25.
Because macOS 25 does not exist. ;-)
Comment by Jolter 3 hours ago
Comment by illithid0 3 hours ago
Comment by ChrisMarshallNY 1 hour ago
iOS 26 anecdote:
A couple of weeks ago, I had a Baltimore Oriole (a cool-looking bird, not a baseball player) in my yard. They aren't rare, per se, but they are uncommon.
Took my iPhone out to snap a picture, and pressed the camera button. I hadn't used it, since upgrading to 26.
It takes the picture. It's there. I can see it, but it won't let me save it. Instead, it wants to tell me about the cool new voice-activated AI retouch feature. There was no way to save.
I probably could have figured it out, but I was so furious, I just nuked the picture.
Comment by dylan604 2 hours ago
For those of us older than just 10 years of using macOS, the older Apple OSes have instilled within us the desire to never install the X.0 release and wait until at least the X.1 release. The bug-free experience is a myth
Comment by pmdr 1 hour ago
Seriously, who the heck even asked for those?
Comment by frizlab 3 hours ago
Comment by reddalo 2 hours ago
Comment by IdiotSavage 2 hours ago
Comment by hbn 2 hours ago
https://www.macrumors.com/2026/06/09/macos-golden-gate-liqui...
Comment by ak217 2 hours ago
Comment by Hamuko 3 hours ago
I might update to macOS 26 in September to be ready to update to macOS 27. Being two versions behind doesn't seem reasonable and I'd rather be on the "Tahoe but less shitty" version than Tahoe itself.
Comment by simlevesque 2 hours ago
Comment by embedding-shape 4 hours ago
Comment by DavideNL 2 hours ago
Comment by embedding-shape 2 hours ago
Yeah, I thought so too, but surprise surprise; some months ago one of the "minor" updates "broke" ("upgraded") something that made my CI/CD setup stop working, that's when I dropped the idea that Apple even do "minor" updates anymore.
Comment by gokohl 2 hours ago
Comment by reddalo 2 hours ago
Then there's me, crying in MacBook Pro 2019 stuck on MacOS 15 because 27 won't be available for my machine.
Comment by ExoticPearTree 3 hours ago
Comment by andreasley 3 hours ago
Comment by bouke 3 hours ago
Comment by carra 3 hours ago
Comment by kylemaxwell 3 hours ago
Comment by hbn 2 hours ago
macOS went from 15 to 26
iOS went from 18 to 26
watchOS went from 11 to 26
and so on
Comment by classified 1 hour ago
Comment by crossroadsguy 3 hours ago
Comment by gedy 2 hours ago
Comment by hbn 2 hours ago
https://youtu.be/VqTn9NgiE1s?t=439
I can't imagine how the people who signed off on that were put in charge of design at Apple.
Comment by gedy 1 hour ago
Then the reality of "what about toolbars", "what about dark mode", "what about laptop screens", etc were all afterthoughts and resulted in bolt-on fixes like that.
Comment by TheJoeMan 2 hours ago
I do not see a "typical" user needing to access a path with say a network storage but multiple ../.. and hard and soft symlinks simultaneously. I think "be liberal in what you accept" might need to be revisited for path parsing with some sort of OS-wide single-implementation as an optional feature.
Comment by acuozzo 1 hour ago
Typical users run software written by atypical users.
> some sort of OS-wide single-implementation
How do you propose handling migration? What if someone tries to expand an old archive file containing a now-forbidden path?
Comment by TheJoeMan 50 minutes ago
Comment by SoftTalker 39 minutes ago
If there's a path on the system that the user should not be able to read, that's the job of the OS to handle, not the individual applications.
Comment by catlifeonmars 1 hour ago
Comment by pjmlp 5 hours ago
Comment by snvzz 4 hours ago
Comment by yjftsjthsd-h 19 minutes ago
Comment by pjmlp 36 minutes ago
Comment by bluecalm 5 hours ago
You need also factor development time and ease of finding developers willing to work in a specific language. There are other factors like readability of the code (very verbose languages are likely to be worse) and cost of maintenance - languages forcing a lot of abstractions are likely much worse.
Comment by acdha 3 hours ago
This even more strongly favors Rust or Swift. Nobody is writing C or even Objective-C in 2026 as a growth language.
Comment by zbentley 2 hours ago
I hope that changes over time, since I definitely agree that the downsides of C-family languages massively outweigh the downsides of competitor languages.
Comment by pjmlp 1 hour ago
C could have gotten slices already in the 90's, the concept already existed in other languages, and even Dennis Ritchie made a fat pointer proposal into that sense.
The others, let see if anything related to profiles actually gets into C++29.
Comment by zbentley 2 hours ago
Citation needed. I don't think there's a correlation there. Over-architected Java spaghetti is verbose and unmaintainable. Under-architected Perl code golf that metastisized is terse and unmaintainable.
> languages forcing a lot of abstractions are likely much worse
Citation needed. C++ has had some very high-level abstractions on top of a low-level runtime for awhile, and plenty of people have decided to use it and hire for it regardless. What counts as an "abstraction" or "forced abstraction" is a very very subjective topic.
Comment by pjmlp 1 hour ago
The problem is the lack of interest since Morris worm came to be, to provide better mechanisms in said languages, until governments and key big tech names decided it was time to change existing practices.
Comment by UqWBcuFx6NV4r 4 hours ago
Comment by embedding-shape 6 hours ago
Comment by woadwarrior01 4 hours ago
Comment by tombot 6 hours ago
Comment by muterad_murilax 5 hours ago
Comment by fnord123 5 hours ago
Comment by mrtksn 5 hours ago
Allegedly of course.
Comment by makeitdouble 3 hours ago
Jony Ive basically works for Open AI (it's more complicated, but it's a good approximation), and has more or less rebuilt a designing team over there.
He's not the central person mentioned in Apple's accusations but that's arguably the central point that's triggering all of this.
Comment by ajmurmann 3 hours ago
Comment by danso 2 hours ago
Comment by alwillis 45 minutes ago
He "took" several Apple employees with him when he left and there's been a steady stream of Apple employees going to OpenAI.
Ive isn’t responsible for all of them obviously, but the articles about lawsuits says there are 400 former Apple employees at OpenAI.
Comment by SoftTalker 34 minutes ago
Comment by anonymars 3 hours ago
Comment by lapcat 3 hours ago
I wouldn't say 4 is lots. The entire list is massive. I haven't counted myself, but someone claimed that macOS 26.6 has the all-time record with 155 CVEs.
Comment by embedding-shape 1 hour ago
Comment by claiir 1 hour ago
Comment by senadir 5 hours ago
Comment by cromka 5 hours ago
Comment by Cider9986 4 hours ago
Comment by pbronez 5 hours ago
Comment by ainch 4 hours ago
Comment by cromka 58 minutes ago
Comment by UqWBcuFx6NV4r 4 hours ago
Comment by bel8 3 hours ago
edit: it seems asking for a source it frowned uppon in this site. And it seems there's no source.
Comment by mholm 2 hours ago
Comment by MBCook 2 hours ago
That would be a very Apple thing to do.
Comment by alwillis 42 minutes ago
That's something Steve Jobs would have done.
Comment by bel8 1 hour ago
And it seems nobody has a source so it's just humors as usual.
Comment by mholm 1 hour ago
Comment by MBCook 2 hours ago
Comment by AJRF 6 hours ago
Are we wink winking that it's a lot of fixes?
Comment by microtonal 4 hours ago
I think the story here is that vulnerability discovery has accelerated a lot with LLMs, but since are adversaries are doing the same, it is more important than ever to update quickly (and not let some Android vendors get away with their lazy update schedules).
[1] https://source.android.com/docs/security/bulletin/2026/2026-... https://source.android.com/docs/security/bulletin/android-17
Comment by cubefox 3 hours ago
Comment by acdha 3 hours ago
Comment by grahamlee 5 hours ago
Comment by Gigachad 2 hours ago
Apple has the advantage that they can keep everything secret for long enough for the patches to roll out. And realistically there is no reason the user needs to know the details of an exploit that was patched before it was ever used.
Comment by DStiego 6 hours ago
AI attribution might be one reason people are particularly curious.
Comment by AJRF 4 hours ago
Comment by cromka 5 hours ago
Comment by nozzlegear 2 hours ago
Comment by cromka 59 minutes ago
Comment by Tepix 5 hours ago
Comment by croemer 6 hours ago
Comment by FabHK 32 minutes ago
Comment by nizbit 6 hours ago
Comment by croemer 6 hours ago
CVE-2026-64691: Ruslan Dautov, Ruslan Dautov
Comment by Someone 4 hours ago
Not necessarily. Could be two persons sharing that name. See https://revstat.ine.pt/index.php/REVSTAT/article/view/382
Comment by proactivesvcs 5 hours ago
CVE-2026-43744: Mathis Mansière, an anonymous researcher
Comment by nkrisc 5 hours ago
Comment by rubslopes 4 hours ago
Comment by darkwater 5 hours ago
Comment by receiptful-io 5 hours ago
Comment by conradfr 5 hours ago