5 ms·
About the security content of macOS Tahoe 26.6
- embedding-shape 2mo agoLots of "in collaboration with Claude and Anthropic Research" mentions, no mentions of other labs. I'd assume Apple already had access to whatever the most powerful model is at the various US-based labs, but perhaps not?
- tombot 2mo agoApple isn’t friends with OpenAI anymore
- muterad_murilax 2mo agoWhat happened?
- fnord123 2mo agohttps://www.cnbc.com/2026/07/10/apple-openai-lawsuit-trade-secrets.html https://www.cnbc.com/2026/07/10/apple-openai-lawsuit-trade-s...
- mrtksn 2mo agoThe gist is, OpenAI hired a high ranking Apple employee who helped other Apple employees get hired by OpenAI and exfiltrate Apple trade secrets in the process. Allegedly of course.
- anonymars 2mo agoThe accusations are pretty wild https://news.ycombinator.com/item?id=48865294 https://news.ycombinator.com/item?id=48865294
- makeitdouble 2mo ago> high ranking Apple employee Jony Ive basically works for Open AI (it's more complicated, but it's a good approximation), and has more or less rebuilt a designing team over there. He's not the central person mentioned in Apple's accusations but that's arguably the central point that's triggering all of this.
- ajmurmann 2mo agoDidn't he live Apple a very long time ago?
- danso 2mo agoYes, the high ranking employee at the center of the accusations is not Ive, but Tang Tan, former VP of product design https://www.bbc.com/news/articles/cy8w379e091o https://www.bbc.com/news/articles/cy8w379e091o
- alwillis 2mo agoHe left in 2019 and formed his own company, that did design work for Apple until 2022. He "took" several Apple employees with him when he left and there's been a steady stream of Apple employees going to OpenAI. Ive isn’t responsible for all of them obviously, but the articles about lawsuits says there are 400 former Apple employees at OpenAI.
- SoftTalker 2mo agoSounds like Apple needs to do a better job at being a place where employees want to stay.
- manmal 2mo agoOr, good that the craze for ever thinner laptops has been slowed?
- acdha 2mo agoGiven that his departure was marked by Apple products getting more reliable and usable, they arguably did too much in that regard (one of Cook’s more notable bad calls). Once he stopped blocking it, the keyboards were fixed and pro devices regained enough ports for pro users. Without his support, his protege Alan Dye left for Meta and improved the design skills at both companies.
- senadir 2mo agoApple also hosts a copy of Claude internally in their servers.
- cromka 2mo agoDo they? As in Claude but on premises? Wonder if this is gonna be the solution that e.g. banks will require, exactly like they do now for cloud services (e.g. Azure on premises).
- pbronez 2mo agoPretty extreme solution… you can get Claude models from AWS Bedrock and Google Model Zoo. These are both very helpful for compliance and security, but do require you to have a cloud strategy.
- ainch 2mo agoSome data is so sensitive it likely has to stay on premises though.
- cromka 2mo agoThat's why banks use Azure on Premises (not sure if other providers offer the same, but the investment bank I worked at did)
- UqWBcuFx6NV4r 2mo agoYeah, albeit an increasingly second-rate experience, at least when it comes to Bedrock.
- Cider9986 2mo agoBanks are all about security theatre so probably not.
- bel8 2mo agosource? edit: it seems asking for a source it frowned uppon in this site. And it seems there's no source.
- woadwarrior01 2mo agoThose were voluntary disclosures by two Anthropic researchers and the security firm Calif. I know one more CVE on the list that was discovered using an AI agent and wasn't disclosed as such. I suspect there are many more.
- lapcat 2mo ago> Lots of "in collaboration with Claude and Anthropic Research" mentions I wouldn't say 4 is lots. The entire list is massive. I haven't counted myself, but someone claimed that macOS 26.6 has the all-time record with 155 CVEs.
- embedding-shape 2mo agoConsidering that in Feb 2026 (https://support.apple.com/en-us/126348 https://support.apple.com/en-us/126348) Claude wasn't mentioned even once, 4 sure sounds like "lots" compared to nothing :) But you're right, it's subjective ultimately.
- claiir 2mo agoalso “ Using GLM From Z.AI”
- AJRF 2mo agoWeird thing to see at number 3 on HN - is there some subtle context I am missing here? Are we wink winking that it's a lot of fixes?
- croemer 2mo agoI think that's it?
- DStiego 2mo agoRelevant context might be for example that there are 4 mentions each of Claude by Anthropic and XGPT by ThreatBook, both based on LLMs. AI attribution might be one reason people are particularly curious.
- AJRF 2mo agoI missed that, thanks for pointing out
- grahamlee 2mo agoAnd it's not actually that much information "about the security content". For example: "Impact: An app may be able to access sensitive user data. Description: An access issue was addressed with additional sandbox restrictions." This references CVE-2026-43819, which doesn't have any more information. Compare this with the nearly decade-old https://support.apple.com/en-gb/103680 https://support.apple.com/en-gb/103680, and you see much more specific information about problems and their remedies (except in situations where Apple's action was to update a vendor component).
- Gigachad 2mo agoThe vagueness could be intentional. There’s been a big issue with linux where proof of concept exploit code gets posted before the bug is announced because people reverse engineer it from the fix commits. Apple has the advantage that they can keep everything secret for long enough for the patches to roll out. And realistically there is no reason the user needs to know the details of an exploit that was patched before it was ever used.
- nizbit 2mo agoCollision counts are absurd. CVE-2026-43739 has roughly twenty credited researchers; CVE-2026-43816 has nearly as many. And ai attribution getting credit.
- croemer 2mo agoOne CVE even lists the same person twice! CVE-2026-64691: Ruslan Dautov, Ruslan Dautov
- proactivesvcs 2mo agoOne of them lists an anonymous person! CVE-2026-43744: Mathis Mansière, an anonymous researcher
- nkrisc 2mo agoIt reads as if "an anonymous researcher" is describing Mathis Mansière, which is quite humorous.
- receiptful-io 2mo agoGenius, that made my day!
- darkwater 2mo agoSpell checker fixed a typo, it was originally "an Anonymous researcher" /s
- rubslopes 2mo agoThis reminds me of my favorite segment of the TV show Curb Your Enthusiasm: https://youtu.be/JqrJ4wGid4Y https://youtu.be/JqrJ4wGid4Y
- conradfr 2mo agoIt's Ted Danson.
- 2mo ago
- pjmlp 2mo agoMap the amount of fixes with "... improved bounds checking...", "...improved memory handling...", "...improved memory management..." into the amount of developer, QA and release management teams salaries per hour, versus other stuff they could be working on, and that gives an approximate value of how using specific languages maps into monetary loss, and why companies are starting to care nowadays, given computers are always exposed to the world network.
- snvzz 2mo agoIf anything, there's a strong argument to switch to seL4.
- deleted 2mo ago[deleted]
- pjmlp 2mo agoIndeed, however without some regulatory help it Will take its time for such kind of improvements across the industry.
- yjftsjthsd-h 2mo agoIt was my vague understanding that by the time you implemented all the apis needed to run normal software on top of that, you either have enough apis that different tasks can still compromise each other, or you have shoved everything into a single task with very little isolation between normal user processes. In either case, it doesn't seem like you actually gained so much. What am I missing?
- bluecalm 2mo ago>>, and that gives an approximate value of how using specific languages maps into monetary loss, and why companies are starting to care nowadays, given computers are always exposed to the world network. You need also factor development time and ease of finding developers willing to work in a specific language. There are other factors like readability of the code (very verbose languages are likely to be worse) and cost of maintenance - languages forcing a lot of abstractions are likely much worse.
- tengwar2 2mo ago15.7.8 is out today as well, with these security fixes: https://support.apple.com/en-us/128071 https://support.apple.com/en-us/128071. For context, there have been issues with MacOS 26 which have led many people to defer upgrading until MacOS 27 is available, and MacOS 15 is the previous version.
- embedding-shape 2mo agoSame thing happens almost every release. I've stopped updating my Mac machine until I see something in the release notes I literally have to have in order to continue doing macOS/iOS builds, otherwise I'm staying on the version I've validated to work, and I know the existing bugs with.
- DavideNL 2mo agoA better strategy would probably be to stick with the previous *major* release, but, do install its ("minor") security updates...
- embedding-shape 2mo ago> do install its ("minor") security updates Yeah, I thought so too, but surprise surprise; some months ago one of the "minor" updates "broke" ("upgraded") something that made my CI/CD setup stop working, that's when I dropped the idea that Apple even do "minor" updates anymore.
- GeekyBear 2mo agoAs we used to say in the Windows world, wait for service pack 3.
- pjmlp 2mo agoThat doesn't work any longer given patch tuesdays, at work wait that IT validates them and pushes the updates via managed WSU, at home, it is worthwhile wanting if something hits the news on WindowsCentral, Verge or what have you.
- TheJoeMan 2mo agoThis may be a naive take, so if anyone has insight please feel free to share, but across Windows, Mac, and Linux OS's I see many cases of path parsing vulnerabilities resulting in sandbox escapes, code execution, or data access issues. When presenting the user with a file picker or command-line input, is it really needed that the software can handle the full POSIX spec? I do not see a "typical" user needing to access a path with say a network storage but multiple ../.. and hard and soft symlinks simultaneously. I think "be liberal in what you accept" might need to be revisited for path parsing with some sort of OS-wide single-implementation as an optional feature.
- catlifeonmars 2mo agoHow would you enforce a single implementation of path parsing?
- acuozzo 2mo ago> I do not see a "typical" user needing to access a path with say... Typical users run software written by atypical users. > some sort of OS-wide single-implementation How do you propose handling migration? What if someone tries to expand an old archive file containing a now-forbidden path?
- TheJoeMan 2mo agoWhat I mean is that for “honest” software, built-in to the OS or otherwise, the programmer finds a situation where they take some user-supplied input and concatenate that into a path, and call something like OS.read(). If they want to prevent the user from causing havoc, they now find themselves dealing with path validation in their software instead of calling OS.safeOpen(), which would be a reduced subset of allowed chars?
- SoftTalker 2mo agoIf the OS is working properly, the havoc should just result in "permission denied." If there's a path on the system that the user should not be able to read, that's the job of the OS to handle, not the individual applications.
- FabHK 2mo agoApropos, anyone else saw "fast user switching" in Tahoe turn into "excruciatingly slow user switching which after a minute of switching without success rebooted the whole damn machine"?
- BoardsOfCanada 2mo agoIt would be so nice to see how many zero-days are going away for bad players right now.
- lovemyMacBookPr 2mo agoQuestions about current version macOS Tahoe 26.5.2 I am noticing that some tabs when clicked or gadgets when oppened, they blink? has anyone experienced this?