
macOS Tahoe Security Patch Fixes Sandbox Escape and Root Privilege Escalation Flaws
Apple's July 28 macOS Tahoe update patches CVE-2026-64737, a sandbox escape letting a malicious app break out entirely, and CVE-2026-43749, a path-parsing flaw enabling root privilege escalation. A third bug, CVE-2026-43748, crashes the system via out-of-bounds write. All require local code execution but pose severe impact in targeted attacks.
Published