About the security content of macOS Tahoe 26.6

(support.apple.com)

33 points | by andor 1 hour ago

3 comments

  • embedding-shape 50 minutes ago
    Lots of "in collaboration with Claude and Anthropic Research" mentions, no mentions of other labs. I'd assume Apple already had access to whatever the most powerful model is at the various US-based labs, but perhaps not?
  • nizbit 42 minutes ago
    Collision counts are absurd. CVE-2026-43739 has roughly twenty credited researchers; CVE-2026-43816 has nearly as many. And ai attribution getting credit.
    • croemer 37 minutes ago
      One CVE even lists the same person twice!

      CVE-2026-64691: Ruslan Dautov, Ruslan Dautov

      • proactivesvcs 27 minutes ago
        One of them lists an anonymous person!

        CVE-2026-43744: Mathis Mansière, an anonymous researcher

        • nkrisc 21 minutes ago
          It reads as if "an anonymous researcher" is describing Mathis Mansière, which is quite humorous.
          • receiptful-io 10 minutes ago
            Genius, that made my day!
          • darkwater 3 minutes ago
            Spell checker fixed a typo, it was originally "an Anonymous researcher" /s
  • AJRF 49 minutes ago
    Weird thing to see at number 3 on HN - is there some subtle context I am missing here?

    Are we wink winking that it's a lot of fixes?

    • grahamlee 20 minutes ago
      And it's not actually that much information "about the security content". For example: "Impact: An app may be able to access sensitive user data. Description: An access issue was addressed with additional sandbox restrictions." This references CVE-2026-43819, which doesn't have any more information. Compare this with the nearly decade-old https://support.apple.com/en-gb/103680, and you see much more specific information about problems and their remedies (except in situations where Apple's action was to update a vendor component).
    • DStiego 37 minutes ago
      Relevant context might be for example that there are 4 mentions each of Claude by Anthropic and XGPT by ThreatBook, both based on LLMs.

      AI attribution might be one reason people are particularly curious.

    • croemer 38 minutes ago
      I think that's it?