Apple released security updates for macOS Sequoia 15.7.5 and macOS Sonoma 14.8.5, patching a wide range of vulnerabilities across core operating system components, networking, printing, privacy controls, the kernel, and bundled open-source software. The advisories describe flaws that could lead to privilege escalation, sandbox escape, unauthorized access to sensitive data, kernel memory disclosure, denial of service, arbitrary file write, and modification of protected file system areas.
Affected components include high-risk areas such as Kernel, CoreServices, CUPS, CFNetwork, NetAuth, SMB, TCC, Security, and PackageKit, with additional privacy-related fixes for apps and services including Mail, Messages, Focus, Phone, and Spotlight. Apple also shipped patches for third-party code in Apache, curl, and ImageIO-related libraries, and credited external researchers and organizations including KU Leuven, Google, Trend Micro Zero Day Initiative, Nosebeard Labs, DBAppSecurity WeBin lab, and Renault researchers for reporting the issues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Apple published security advisory APPLE-SA-03-24-2026-5 for macOS Sonoma 14.8.5, detailing fixes for numerous vulnerabilities affecting components such as CoreServices, CUPS, NetAuth, SMB, TCC, Security, PackageKit, the Kernel, and open-source packages. Apple said the update was available through the Mac App Store and its software download channels.
Apple published security advisory APPLE-SA-03-24-2026-4 for macOS Sequoia 15.7.5, fixing a broad set of vulnerabilities across core OS components, networking, kernel, privacy controls, printing, and bundled open-source software. The update addressed issues including sensitive data access, sandbox escape, privilege escalation, arbitrary file write, denial of service, kernel memory disclosure, and protected file system modification.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcesupport.apple.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.