About the security content of macOS Tahoe 26.6
support.apple.com
support.apple.com
For context, there have been issues with MacOS 26 which have led many people to defer upgrading until MacOS 27 is available, and MacOS 15 is the previous version.
For me the issue is liquid glass. Which I doubt is getting fixed any time soon
https://www.cultofmac.com/news/liquid-glass-changes-ios-27-m...
Having installed the beta, I think that's the best you can say about it.
Nothing will ever be as good as 25.
Because macOS 25 does not exist. ;-)
iOS 26 anecdote:
A couple of weeks ago, I had a Baltimore Oriole (a cool-looking bird, not a baseball player) in my yard. They aren't rare, per se, but they are uncommon.
Took my iPhone out to snap a picture, and pressed the camera button. I hadn't used it, since upgrading to 26.
It takes the picture. It's there. I can see it, but it won't let me save it. Instead, it wants to tell me about the cool new voice-activated AI retouch feature. There was no way to save.
I probably could have figured it out, but I was so furious, I just nuked the picture.
Fairly typical kind of workflow, that most apps do, these days. It’s just that the timing couldn’t have been worse.
> You must be a bot, just another living shill. another confident user error in the field
I have no idea what that means.
For those of us older than just 10 years of using macOS, the older Apple OSes have instilled within us the desire to never install the X.0 release and wait until at least the X.1 release. The bug-free experience is a myth
I think that applies to almost all software, not just Apple OSes. After all, Confucius said: "The only thing worse than old software is new software."
I had that turned off years ago (for reasons I don't remember), and was wondering what all the fuzz was about when 26 came out because I didn't see much of a difference ;)
IMHO the actual important visual changes in the 27 beta is that rolls back the bizarre oversized corner radius in Finder windows, and they also got rid of the 'every menu item must have an icon' idea.
I might update to macOS 26 in September to be ready to update to macOS 27. Being two versions behind doesn't seem reasonable and I'd rather be on the "Tahoe but less shitty" version than Tahoe itself.
Seriously, who the heck even asked for those?
https://www.macrumors.com/2026/06/09/macos-golden-gate-liqui...
I recently made the move away from an out-of-support macOS 12 Monterey to Debian Stable (13 trixie), after some failed attempts to upgrade macOS using OpenCore Legacy Patcher.
While Linux support will always remain far from perfect with that series of MBP, it was still much better than I expected compared to my last look many years ago. I happen to get better use out of my particular setup now compared to macOS; as it's basically a glorified streaming device that I interact with through wayvnc/vncviewer out of arm's reach across a table. This also allows me to mostly avoid using the semi-busted Butterfly keyboard.
In addition to having something with security updates again, I'll now never need to think about Apple dropping Intel support. I'd also like to note that nix-darwin support on Intel macOS is ending very soon too - but not Linux + nix as a package manager (nixpkgs) since that combination is separate to macOS + nix-darwin.
However, Software Update on Apple devices still allows you to turn off automatic update installation the way Windows used to.
For quite some time that I don't use home edition.
I also would not bet on Apple staying that way.
It's right up there with Microsoft's "you are not allowed to turn telemetry all the way off", or all the efforts to require the use of an online Microsoft account to access your own computer.
Ever heard of Local Group Policy Editor?
Secure Boot initially didn't allow the install of operating systems other than Windows.
Microsoft is the company continually attempting to lock down their general purpose computers, not Apple.
...and no. Microsoft backing down aftet consumers revolt doesn't mean their attempts don't count.
Yeah, I thought so too, but surprise surprise; some months ago one of the "minor" updates "broke" ("upgraded") something that made my CI/CD setup stop working, that's when I dropped the idea that Apple even do "minor" updates anymore.
Then there's me, crying in MacBook Pro 2019 stuck on MacOS 15 because 27 won't be available for my machine.
macOS went from 15 to 26
iOS went from 18 to 26
watchOS went from 11 to 26
and so on
https://youtu.be/VqTn9NgiE1s?t=439
I can't imagine how the people who signed off on that were put in charge of design at Apple.
Then the reality of "what about toolbars", "what about dark mode", "what about laptop screens", etc were all afterthoughts and resulted in bolt-on fixes like that.
You need also factor development time and ease of finding developers willing to work in a specific language. There are other factors like readability of the code (very verbose languages are likely to be worse) and cost of maintenance - languages forcing a lot of abstractions are likely much worse.
This even more strongly favors Rust or Swift. Nobody is writing C or even Objective-C in 2026 as a growth language.
I hope that changes over time, since I definitely agree that the downsides of C-family languages massively outweigh the downsides of competitor languages.
C could have gotten slices already in the 90's, the concept already existed in other languages, and even Dennis Ritchie made a fat pointer proposal into that sense.
The others, let see if anything related to profiles actually gets into C++29.
Citation needed. I don't think there's a correlation there. Over-architected Java spaghetti is verbose and unmaintainable. Under-architected Perl code golf that metastisized is terse and unmaintainable.
> languages forcing a lot of abstractions are likely much worse
Citation needed. C++ has had some very high-level abstractions on top of a low-level runtime for awhile, and plenty of people have decided to use it and hire for it regardless. What counts as an "abstraction" or "forced abstraction" is a very very subjective topic.
The problem is the lack of interest since Morris worm came to be, to provide better mechanisms in said languages, until governments and key big tech names decided it was time to change existing practices.
Allegedly of course.
Jony Ive basically works for Open AI (it's more complicated, but it's a good approximation), and has more or less rebuilt a designing team over there.
He's not the central person mentioned in Apple's accusations but that's arguably the central point that's triggering all of this.
He "took" several Apple employees with him when he left and there's been a steady stream of Apple employees going to OpenAI.
Ive isn’t responsible for all of them obviously, but the articles about lawsuits says there are 400 former Apple employees at OpenAI.
Without his support, his protege Alan Dye left for Meta and improved the design skills at both companies.
I wouldn't say 4 is lots. The entire list is massive. I haven't counted myself, but someone claimed that macOS 26.6 has the all-time record with 155 CVEs.
edit: it seems asking for a source it frowned uppon in this site. And it seems there's no source.
That would be a very Apple thing to do.
And it seems nobody has a source so it's just humors as usual.
That's something Steve Jobs would have done.
Are we wink winking that it's a lot of fixes?
I think the story here is that vulnerability discovery has accelerated a lot with LLMs, but since are adversaries are doing the same, it is more important than ever to update quickly (and not let some Android vendors get away with their lazy update schedules).
[1] https://source.android.com/docs/security/bulletin/2026/2026-... https://source.android.com/docs/security/bulletin/android-17
Apple has the advantage that they can keep everything secret for long enough for the patches to roll out. And realistically there is no reason the user needs to know the details of an exploit that was patched before it was ever used.
But since this is never known, does the user need to know?
AI attribution might be one reason people are particularly curious.
I do not see a "typical" user needing to access a path with say a network storage but multiple ../.. and hard and soft symlinks simultaneously. I think "be liberal in what you accept" might need to be revisited for path parsing with some sort of OS-wide single-implementation as an optional feature.
Typical users run software written by atypical users.
> some sort of OS-wide single-implementation
How do you propose handling migration? What if someone tries to expand an old archive file containing a now-forbidden path?
If there's a path on the system that the user should not be able to read, that's the job of the OS to handle, not the individual applications.
CVE-2026-64691: Ruslan Dautov, Ruslan Dautov
Not necessarily. Could be two persons sharing that name. See https://revstat.ine.pt/index.php/REVSTAT/article/view/382
CVE-2026-43744: Mathis Mansière, an anonymous researcher