Release appearance

macOS 26.6.2 Public

Full article
Public release

Recorded context

About this appearance

Apple released macOS Tahoe 26.6.2 on August 17, 2026 as build 25G83, seven days after seeding build 25G82 as the first beta and eleven days after macOS 26.6.1 reached the public. The advisory lists twenty-eight distinct CVE identifiers across seven components.

Date
Aug 17, 2026
Availability
available
Revision
No
Build
25G83

Release notes

What changed

Original editorial synthesis. Linked references appear with the claims they support and in the source ledger.

macOS Tahoe 26.6.2 reached public release on August 17, 2026 as build 25G83. Its security document, Apple advisory 148281, contains 20 entries covering 28 distinct CVE identifiers across seven component headings: Audio, ImageIO, IOGPUFamily, Kernel, WebKit, WebKit History, and WebKit Storage. Every entry carries the same availability line, "Available for: macOS Tahoe", with no hardware or configuration carve-outs. Beyond the 20 vulnerability entries the document carries only an Additional recognition section, and Apple published no accompanying feature notes for the build.

The Mac list is the iPhone and iPad list with one subtraction. Compared against advisory 148282, published the same day for iOS 26.6.1 and iPadOS 26.6.1, the two documents share 28 identifiers, and the only difference is CVE-2026-65329 under Telephony, which appears in the iOS advisory scoped to iPhone and does not appear on the Mac at all. The internal shape matches too. WebKit accounts for 19 of the 28 identifiers, with WebKit History and WebKit Storage adding one each, so 21 of 28 fixes are in the browser engine and its adjacent layers. Kernel carries three, ImageIO two, and Audio and IOGPUFamily one each. Nine of the WebKit credit lines name OpenAI Codex Security, eight of them as sole finder attributed to Amy Burnett and one, CVE-2026-64784, shared with Janggoon Lee of Out of Bounds.

Apple states where the fixes came from in the advisory's first sentence: "This update delivers security fixes that were first made available in the macOS Golden Gate 27 beta." The wording names the unreleased successor by its release name and places the patches there ahead of the shipping Tahoe train.

The release also sits 11 days after another security update to the same operating system, and the two look nothing alike. macOS Tahoe 26.6.1 shipped on August 6, 2026 with exactly one entry: a Screen Sharing authentication flaw, CVE-2026-65400, described as letting an attacker on the network authenticate without valid credentials, credited to Alfredo Pesoli via Bynario Atlas. Eleven days later, 26.6.2 arrived with 28 identifiers across seven components. One release was a single targeted fix, the next a broad security update. The shipping build moved between candidate and release as well: Apple seeded 25G82 on August 10 and shipped 25G83 on August 17, one increment higher. No reason has been published, and none of the 28 entries refers to exploitation.

Source ledger

References

Sources are linked to the claims they support. Publication and access dates are shown when available.

  1. Releases - Apple Developer

    Apple Developer · Apple · 2026-07-29 · macOS 26.6.2 (25G83); August 17, 2026

  2. About the security content of macOS Tahoe 26.6.2

    Apple Support · 2026-08-17T00:00:00Z · macOS Tahoe 26.6.2; Released August 17, 2026

  3. About the security content of macOS Tahoe 26.6.2

    Apple Support · 2026-08-17T00:00:00Z · Section heading "macOS Tahoe 26.6.2", line "Released August 17, 2026", followed by all 20 component entries through the end of the document

  4. Releases - Apple Developer

    Apple Developer · Apple · 2026-07-29 · Releases list, entry "macOS 26.6.2 (25G83)" dated August 17, 2026

  5. About the security content of macOS Tahoe 26.6.2

    Apple Support · 2026-08-17T00:00:00Z · Full list of 28 CVE identifiers under "macOS Tahoe 26.6.2", "Released August 17, 2026"

  6. About the security content of iOS 26.6.1 and iPadOS 26.6.1

    Apple Support · 2026-08-17T00:00:00Z · Full list of 29 CVE identifiers under "iOS 26.6.1 and iPadOS 26.6.1", including the Telephony section entry CVE-2026-65329 marked "Available for: iPhone 11 and later"

  7. About the security content of macOS Tahoe 26.6.2

    Apple Support · 2026-08-17T00:00:00Z · WebKit, WebKit History, and WebKit Storage entries and their credit lines, counted against the Audio, ImageIO, IOGPUFamily, and Kernel entries in the same document

  8. About the security content of macOS Tahoe 26.6.2

    Apple Support · 2026-08-17T00:00:00Z · Opening paragraph, first sentence, immediately above the "About Apple security updates" heading

  9. About the security content of macOS Tahoe 26.6.1

    Apple Support · 2026-08-06T00:00:00Z · Section "macOS Tahoe 26.6.1", line "Released August 6, 2026", Screen Sharing entry with Impact, Description, and the CVE-2026-65400 credit line; the document contains no other entry

  10. About the security content of macOS Tahoe 26.6.2

    Apple Support · 2026-08-17T00:00:00Z · Section "macOS Tahoe 26.6.2", line "Released August 17, 2026", 20 entries covering 28 CVE identifiers

  11. Apple preps beta security updates for iOS 18, iOS 26, and macOS 26

    AppleInsider · 2026-08-10T00:00:00Z · Article body sentence giving the macOS 26.6.2 beta build number as 25G82

  12. Apple Releases macOS Tahoe 26.6.2 Beta With Security Fixes

    MacRumors · 2026-08-17 · Article body and correction note identifying the August 10 macOS Tahoe 26.6.2 seed as build 25G82

Release changes

Changed in this release

Features, fixes, removals, and regressions first observed in this release record.

security · fixed

Security-only release with 28 CVEs across seven components

undocumentedcorroborated

macOS Tahoe 26.6.2 (25G83) shipped on August 17, 2026 with 20 advisory entries covering 28 distinct CVE identifiers across Audio, ImageIO, IOGPUFamily, Kernel, WebKit, WebKit History, and WebKit Storage. Every entry reads "Available for: macOS Tahoe", and no feature or interface change is documented.

  1. [1] About the security content of macOS Tahoe 26.6.2 · Section heading "macOS Tahoe 26.6.2", line "Released August 17, 2026", followed by all 20 component entries through the end of the document
  2. [2] Releases - Apple Developer · Releases list, entry "macOS 26.6.2 (25G83)" dated August 17, 2026

security · fixed

Mac CVE set is the iOS set minus the iPhone-only Telephony fix

undocumentedcorroborated

Comparing advisory 148281 against advisory 148282, published the same day, the two share 28 identifiers and differ by exactly one: CVE-2026-65329 under Telephony, present in the iOS document and scoped to iPhone, is absent from the Mac document. No Mac identifier is missing from the iOS list.

  1. [1] About the security content of macOS Tahoe 26.6.2 · Full list of 28 CVE identifiers under "macOS Tahoe 26.6.2", "Released August 17, 2026"
  2. [2] About the security content of iOS 26.6.1 and iPadOS 26.6.1 · Full list of 29 CVE identifiers under "iOS 26.6.1 and iPadOS 26.6.1", including the Telephony section entry CVE-2026-65329 marked "Available for: iPhone 11 and later"

security · fixed

21 of 28 fixes land in WebKit components, nine credited to OpenAI Codex Security

undocumentedreported

WebKit accounts for 19 of the 28 identifiers, with WebKit History and WebKit Storage adding one each for 21 of 28 in the browser engine and its adjacent layers. Nine WebKit credit lines name OpenAI Codex Security: CVE-2026-64780, CVE-2026-64784, CVE-2026-65331, CVE-2026-65332, CVE-2026-65333, CVE-2026-65334, CVE-2026-65335, CVE-2026-65337, and CVE-2026-65338. Eight credit it alone, attributed to Amy Burnett; CVE-2026-64784 shares credit with Janggoon Lee of Out of Bounds.

  1. [1] About the security content of macOS Tahoe 26.6.2 · WebKit, WebKit History, and WebKit Storage entries and their credit lines, counted against the Audio, ImageIO, IOGPUFamily, and Kernel entries in the same document

behavior · introduced

Advisory states the fixes reached the macOS Golden Gate 27 beta first

undocumentedreported

The advisory opens with "This update delivers security fixes that were first made available in the macOS Golden Gate 27 beta." Apple names the unreleased successor by release name and places the patches there ahead of the shipping Tahoe train, making 26.6.2 the backport.

  1. [1] About the security content of macOS Tahoe 26.6.2 · Opening paragraph, first sentence, immediately above the "About Apple security updates" heading

behavior · changed

Arrives 11 days after a one-CVE predecessor

undocumentedcorroborated

macOS Tahoe 26.6.1 shipped on August 6, 2026 with a single entry, the Screen Sharing authentication flaw CVE-2026-65400, described as letting an attacker on the network authenticate without valid credentials and credited to Alfredo Pesoli via Bynario Atlas. macOS Tahoe 26.6.2 followed 11 days later with 28 identifiers across seven components.

  1. [1] About the security content of macOS Tahoe 26.6.1 · Section "macOS Tahoe 26.6.1", line "Released August 6, 2026", Screen Sharing entry with Impact, Description, and the CVE-2026-65400 credit line; the document contains no other entry
  2. [2] About the security content of macOS Tahoe 26.6.2 · Section "macOS Tahoe 26.6.2", line "Released August 17, 2026", 20 entries covering 28 CVE identifiers

behavior · changed

Shipping build is one increment above the August 10 candidate

undocumentedcorroborated

macOS 26.6.2 was seeded as build 25G82 on August 10, 2026 and shipped as 25G83 on August 17, one increment higher. Apple has published no explanation for the respin, and the advisory contains no reference to exploitation.

  1. [1] Releases - Apple Developer · Releases list, entry "macOS 26.6.2 (25G83)" dated August 17, 2026
  2. [2] Apple preps beta security updates for iOS 18, iOS 26, and macOS 26 · Article body sentence giving the macOS 26.6.2 beta build number as 25G82
  3. [3] Apple Releases macOS Tahoe 26.6.2 Beta With Security Fixes · Article body and correction note identifying the August 10 macOS Tahoe 26.6.2 seed as build 25G82