Apple has released macOS Tahoe 26.7.1 with a security fix for a vulnerability connected to highly targeted attacks. Mac owners remaining on Tahoe should install the update promptly, particularly when the computer handles sensitive files or communications.
Apple’s security advisory for macOS Tahoe 26.7.1 identifies the issue as CVE-2026-86950 in CoreGraphics. Processing a maliciously crafted file could lead to arbitrary code execution, and Apple says the underlying flaw may have been exploited in an extremely sophisticated attack against specific individuals using iOS versions older than iOS 27.
What the Tahoe security update fixes
The flaw is an out-of-bounds write, a memory-safety problem that can allow data to be written outside its intended location. Apple says it corrected the issue with improved bounds checking. Meta Product Security received credit for reporting the vulnerability.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
Apple’s wording is deliberately narrow. It does not say every Mac was attacked, and its exploitation statement refers specifically to targeted people using older iOS versions. The same CoreGraphics weakness still receives a patch in Tahoe, which makes installing the Mac update the safer choice even without evidence of widespread exploitation on macOS.
macOS Tahoe 26.7.1 is especially relevant to Intel Mac users because macOS 27 requires Apple silicon. Apple also released macOS 27.0.1 for eligible newer Macs, but that release has no published CVE entry for this vulnerability. Users should install the update offered for their current operating system rather than assume the newest version number applies to every Mac.
How to update a Mac running Tahoe
Open System Settings, select General and choose Software Update. Save current work and back up important data before starting the installation. The Mac will need to restart to complete the process.
MacObserver previously examined how Apple’s security support differs across macOS generations. In this case, Tahoe and Sequoia received corresponding updates, while Golden Gate follows its own maintenance track.
Discussion