
macOS Tahoe Patch Fixes Sandbox Escape and Root Privilege Escalation Flaws
Apple's July 28 macOS Tahoe security update patches CVE-2026-64737, a sandbox escape allowing a malicious app to break out entirely, and CVE-2026-43749, a directory-path parsing flaw enabling root privilege escalation. A third bug, CVE-2026-43748, causes system termination via out-of-bounds write. All require local code execution as a prerequisite but carry severe impact in targeted attack scenarios.
Published