macOS Patch Closes Trust-Boundary Breaks

macOS is getting more than routine cleanup here. The patch set closes places where the platform would trust the wrong thing — sandboxing, Gatekeeper, permissions, and memory handling — so a local app can cross into sensitive data, higher privilege, or code execution. Apple fixed multiple flaws in Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.x. The advisory covers sandbox escapes, Gatekeeper bypasses via crafted ZIP archives, input and path validation bugs, and memory corruption issues including use-after-free, buffer overflows, out-of-bounds access, and type confusion. For managed Macs, the usual 'desktop update' framing is too light. These bugs sit in the controls that keep a local foothold contained, so a single compromised user session can become broader access on the workstation layer.

Part of the PlainSec briefing for 2026-07-28

Sources