www.macwelt.de Apple Releases Critical Security Updates for macOS Golden Gate and Others
Article Content
- •CVE-2026-86950 allows arbitrary code execution through CoreGraphics.
- •Updates released for macOS Golden Gate, Tahoe, and Sequoia on September 29, 2026.
- •No CVEs reported for macOS Golden Gate 27.0.1, but critical vulnerabilities exist in Tahoe and Sequoia.
On September 29, 2026, Apple released updates for macOS Golden Gate 27.0.1, Tahoe 26.7.1, and Sequoia 15.8.1. The updates for Tahoe and Sequoia address a critical vulnerability (CVE-2026-86950) in CoreGraphics that allows for arbitrary code execution via manipulated files. This vulnerability was reportedly exploited in sophisticated attacks targeting specific individuals using iOS versions prior to iOS 27. Apple has not disclosed any CVE entries for the Golden Gate update itself. Users are advised to install these updates to mitigate potential risks. The updates follow a three-month beta testing period for the new macOS versions, which were released just two weeks prior. Apple also addressed bugs in iOS 27.0.1 and watchOS 27.0.1, which included issues causing device crashes and screen freezes.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-86950 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
High-Risk Remote Code Execution Vulnerability in Apple Products A critical vulnerability, CVE-2026-86950, has been identified in Apple products, allowing remote code execution via maliciously crafted files. This issue affects versions of iOS prior to 26.7.1, iPadOS prior to 26.7.1, macOS Sequoia prior to 15.8.1, and macOS Tahoe prior to 26.7.1. Apple has acknowledged that this…
Apple Patches CoreGraphics Zero-Day Exploited in Targeted Attacks Apple has released security updates for iOS, iPadOS, and macOS to address CVE-2026-86950, a zero-day vulnerability in CoreGraphics that may have been exploited in targeted attacks against specific individuals. The flaw, an out-of-bounds write issue, allows arbitrary code execution when processing specially crafted…