macOS Tahoe 26.7 and Sequoia 15.8 are Out--More Than 150 Security Fixes Each, No New Features, and the First Update the Intel Macs Get Without Golden Gate

macOS Tahoe 26.7 and macOS Sequoia 15.8 are out. Apple released both on September 14, the day macOS 27 Golden Gate shipped, and Apple's release notes for 26.7 say only that it "provides important security fixes and is recommended for all users." It is the first update since Golden Gate for the four Intel Macs that run Tahoe and cannot run 27, and for anyone else staying put, and by our count of Apple's security page it closes 153 holes.
Nothing but security fixes, and most of them are Golden Gate's
There are no features. 9to5Mac has the builds as 25G229 for Tahoe and 24H23 for Sequoia. We compared the CVE identifiers on Apple's three pages: macOS Golden Gate 27's lists 210, Tahoe 26.7's lists 153 and Sequoia 15.8's lists 154. Of Tahoe's 153, 149 are also in Golden Gate and 140 are on all three pages. The 61 that appear only in Golden Gate are mostly single entries in parts the older systems do not share, Apple Intelligence, Siri, Safe Browsing and System Settings among them, plus six in the kernel and three in WebKit. Howard Oakley at The Eclectic Light Company counts around 206 items for Golden Gate and says none of them is suspected of being exploited in the wild; no entry on the Tahoe or Sequoia page says so either.
The Tahoe page has 27 entries under Kernel, and nine under CUPS, the printing system, two of which read "An app may be able to gain root privileges" and one "A remote user may cause an unexpected app termination or arbitrary code execution." One Bluetooth entry, CVE-2026-65414, says "A remote attacker may be able to cause unexpected app termination or arbitrary code execution." An autofs entry lets "an attacker with control of a network directory server" run code as root, a udf entry lets an app "execute arbitrary code with kernel privileges," and four entries, in autofs, copyfile, CoreServices and the kernel, are Gatekeeper bypasses. The Sequoia page adds an ImageIO entry, "Processing an image may lead to arbitrary code execution," that is not on Tahoe's. Neither page lists WebKit; those fixes come as Safari 27, a separate update for Sequoia and Tahoe released the same day with six entries of its own.
Who this update is for
Golden Gate requires an Apple silicon Mac, and Apple's compatibility list for Tahoe still carries four Intel models: the MacBook Pro (16-inch, 2019), the MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), the iMac (Retina 5K, 27-inch, 2020) and the Mac Pro (2019). For those, 26.7 is the road from here, as we said in our September 9 tip on the Intel Mac after Golden Gate. MacRumors puts the audience as "users with older Macs or those who don't yet want to update to Golden Gate."
How long the road runs, Apple does not say. Oakley writes that Tahoe is "starting its first two years of security-only support" and Sequoia "its final year," and that Sonoma is now unsupported; Apple's security releases page lists no Sonoma update on September 14; the newest macOS Sonoma entry is 14.8.9 of August 6, and the Safari 27 line names only Sequoia and Tahoe. The pattern is old. Apple agreed to keep patching Jaguar after Panther shipped, as our November 2003 note on the promise recorded, and Panther was still getting patches when our November 2007 note on Security Update 2007-008 called it the likely end of the line, with Leopard out and Tiger the previous release.
What to do now
Open System Settings, click General, then Software Update. If Software Update offers Golden Gate as well, choosing 26.7 keeps you on Tahoe with the 149 fixes it shares with Golden Gate, by our count. Oakley notes that the Apple silicon boot firmware moves to 20457.1.29 in all three releases, so an Apple silicon Mac staying on Tahoe gets the same firmware as one moving up. Install Safari 27 with it; the WebKit fixes are there, not in 26.7. The details of what Golden Gate itself changes are in our September 15 report on macOS 27.
We will post a hands-on report once we have installed 26.7 on an Intel Mac. A hundred and fifty fixes for a Mac from 2019 or 2020 is the better half of the Intel bargain; take it.
Sources
- Apple Support, “About the security content of macOS Tahoe 26.7” accessed Sep 19, 2026
The September 14, 2026 release date; "Available for: macOS Tahoe"; the entries we counted (153 distinct CVE identifiers, 27 under Kernel, nine under CUPS with two reading "An app may be able to gain root privileges" and one "A remote user may cause an unexpected app termination or arbitrary code execution"); the Bluetooth entry CVE-2026-65414 and its impact text; the autofs, udf and Gatekeeper-bypass entries; that no entry says an issue was exploited; and that WebKit is not listed.
- Apple Support, “About the security content of macOS Sequoia 15.8” accessed Sep 19, 2026
The September 14, 2026 release date; "Available for: macOS Sequoia"; the 154 distinct CVE identifiers we counted; the ImageIO entry "Processing an image may lead to arbitrary code execution" that is absent from the Tahoe page; that no entry says an issue was exploited; and that WebKit is not listed.
- Apple Support, “About the security content of macOS Golden Gate 27” accessed Sep 19, 2026
The 210 distinct CVE identifiers we counted, the "Available for" line naming only Apple silicon Macs and the MacBook Neo, and the components of the 61 entries that are not on the Tahoe 26.7 page (Apple Intelligence, Siri, Safe Browsing, System Settings, six in the kernel, three in WebKit).
- Apple Support, “Apple security releases” accessed Sep 19, 2026
The September 14, 2026 table entries for macOS Golden Gate 27, macOS Tahoe 26.7, macOS Sequoia 15.8 and Safari 27 ("macOS Sequoia and macOS Tahoe"); no Sonoma entry on that date, the newest macOS Sonoma entry being 14.8.9 on August 6, 2026, and the Safari 27 line naming only Sequoia and Tahoe.
- Apple Support, “What's new in the updates for macOS Tahoe 26” accessed Sep 19, 2026
The macOS Tahoe 26.7 release note: "This update provides important security fixes and is recommended for all users."
- Apple Support, “macOS Tahoe 26 is compatible with these computers” accessed Sep 19, 2026
The four Intel models on the Tahoe list, as Apple names them: MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), iMac (Retina 5K, 27-inch, 2020) and Mac Pro (2019).
- Apple Support, “About the security content of Safari 27” accessed Sep 19, 2026
Safari 27 released September 14, 2026, "Available for: macOS Sequoia and macOS Tahoe," with six CVE identifiers by our count.
- MacRumors, “Apple Releases macOS Tahoe 26.7 and macOS Sequoia 15.8” accessed Sep 19, 2026
Juli Clover's September 14 report that the two updates are "available for users with older Macs or those who don't yet want to update to Golden Gate," through Software Update in System Settings.
- 9to5Mac, “Apple releases macOS Tahoe 26.7 and macOS Sequoia 15.8, here's what's new” accessed Sep 19, 2026
Marcus Mendes's September 14 report supplies the build numbers, 25G229 for Tahoe 26.7 and 24H23 for Sequoia 15.8.
- The Eclectic Light Company, “Apple has released macOS Golden Gate, and security updates to Tahoe 26.7, Sequoia 15.8” accessed Sep 19, 2026
Howard Oakley's September 14 post: Tahoe 26.7 "starting its first two years of security-only support" and Sequoia 15.8 "starting its final year"; no security update to Sonoma, "which is now unsupported"; Golden Gate's security notes listing "around 206 items, none of them suspected of being exploited in the wild"; and the Apple silicon boot firmware 20457.1.29 "also in 26.7 and 15.8."
Saw something? Send a tip or a correction
The archive ran on reader tips. What did you see, where, and do you want the credit? Something wrong on this page? Say so and it gets fixed.