CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude(support.apple.com) |
CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude(support.apple.com) |
Since mid-April Chrome showed 302 vulnerabilities patched, 225 of them found by Google. Same period last year was 19 vulnerabilities. They've also become more transparent recently, disclosing vulnerabilities found internally, not just externally (which Apple still doesn't appear to do). From the outside, it's hard to tell if Apple has deployed this tooling as much as Google.
> The affected releases include iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.
I’ve already seen a lot of people self-congratulating for not updating to Tahoe but this isn’t exclusive to Tahoe.
Where does this quote come from? I can't see it in https://support.apple.com/en-us/127115, the article link at time of writing.
I can do a google search for "CVE-2026-28952", and find various pages. Here's one, for example: https://www.cve.org/CVERecord?id=CVE-2026-28952 - and it sounds like the releases "affected", which I at least would take to refer to the releases in which the issue is present, are the ones in which the issue is in fact fixed:
> This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5
Impact: An app may be able to cause unexpected system termination
Description: An integer overflow was addressed with improved input validation.
CVE-2026-28952: Calif.io in collaboration with Claude and Anthropic Research
Assuming Apple has deployed all of these and have invested in the labor/training on how to properly use them.
>Our engineers, working together with Mythos Preview, built a working exploit in five days.
I wonder if this will change general dynamics -- feels like LTS releases could become even more important, at the same time having reduced maintenance costs since you can have some agentic help on backporting.
e.g. macOS 15.0, 15.1, 15.3, 15.4, 15.6 and 15.7 all had .1 patches within a few weeks of release.
1000 different companies will be pitching your CTO their proprietary vulnerability scanning harness as the most cost effective.
Sequoia also has security bugs :) https://support.apple.com/en-us/127116