Views
20

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

Update Summary

macOS Sonoma 14.8.7 includes security fixes for APFS, Kernel, Wi-Fi, mDNSResponder, and other components. Apple lists multiple CVEs, including CVE-2026-28959, CVE-2026-28915, and CVE-2026-39871.

Update Details

Security

  • APFS: buffer overflow could cause unexpected system termination; improved bounds checking (CVE-2026-28959)
  • AppleJPEG: memory corruption in malicious media processing could terminate the app or corrupt memory (CVE-2026-28956)
  • Audio: malicious media could terminate the process; improved memory handling (CVE-2026-39869)
  • CoreMedia: app could access private information; improved state management (CVE-2026-28922)
  • CUPS: app could gain root privileges; improved path validation (CVE-2026-28915)
  • FileProvider: race condition could expose sensitive user data; additional validation (CVE-2026-43659)
  • GPU Drivers: malicious app could break out of its sandbox; improved data redaction (CVE-2026-28923)
  • HFS: buffer overflow could cause system termination or write kernel memory; improved bounds checking (CVE-2026-28925)
  • Icons: app could break out of its sandbox; additional sandbox restrictions (CVE-2025-43524)
  • Installer: malicious app could break out of its sandbox; additional restrictions (CVE-2026-28978)
  • IOHIDFamily: memory corruption could cause unexpected app termination; improved locking (CVE-2026-28992)
  • IOHIDFamily: logging issue could reveal kernel memory layout; improved data redaction (CVE-2026-28943)
  • IOKit: use-after-free could cause system termination; improved memory management (CVE-2026-28969)
  • Kernel: kernel memory disclosure; improved memory handling (CVE-2026-43654)
  • Kernel: file quarantine bypass could let a malicious disk image bypass Gatekeeper checks (CVE-2026-28954)
  • Kernel: buffer overflow could cause system termination or read kernel memory; improved input validation (CVE-2026-28897)
  • Kernel: integer overflow could cause system termination; improved input validation (CVE-2026-28952)
  • Kernel: vulnerable code removed to prevent modification of protected file system areas (CVE-2026-28908)
  • Kernel: authorization issue could allow root privileges; improved state management (CVE-2026-28951)
  • Kernel: out-of-bounds write could cause system termination or write kernel memory; improved input validation (CVE-2026-28972)
  • Kernel: logging issue could leak sensitive kernel state; improved data redaction (CVE-2026-28986)
  • Mail Drafts: Lockdown Mode could display remote images when replying; improved checks (CVE-2026-28987)
  • mDNSResponder: local-network denial of service; improved memory handling (CVE-2026-28929)
  • mDNSResponder: remote use-after-free could cause system termination or kernel memory corruption; improved memory management (CVE-2026-43653)
  • mDNSResponder: out-of-bounds write could cause local-network denial of service; improved bounds checking (CVE-2026-43668)
  • Networking: IP address tracking issue; improved state management (CVE-2026-43666)
  • PackageKit: permissions issue could allow root privileges; additional restrictions (CVE-2026-28906)
  • Quick Look: malicious file could cause app termination; improved input validation (CVE-2026-28840)
  • SceneKit: malicious image could corrupt memory; improved memory handling (CVE-2026-43656)
  • SceneKit: remote attacker could cause app termination; improved bounds checking (CVE-2026-39870)
  • Shortcuts: user-sensitive data access required an additional consent prompt (CVE-2026-28846)
  • Storage: race condition could expose sensitive user data; additional validation (CVE-2026-28993)
  • StorageKit: app could gain root privileges; improved state handling (CVE-2026-28996)
  • Sync Services: app could access Contacts without user consent; improved symbolic link handling (CVE-2026-28919)
  • TV App: path handling issue could expose unprotected user data; improved logic (CVE-2026-28924)
  • Wi-Fi: out-of-bounds write could allow arbitrary code with kernel privileges; improved bounds checking (CVE-2026-39871)
  • Wi-Fi: use-after-free could enable denial of service from a privileged network position; improved memory management (CVE-2026-28819)
  • zlib: malicious website could leak sensitive data; additional validation (CVE-2026-28994)

Hints

  • Released for macOS Sonoma.
  • Apple security documents reference vulnerabilities by CVE-ID when possible.
Product Information

Vendor: Apple

Product: macOS

Product type: Other

Application category: Utilities

Platform: macOS

Variant: Sonoma (14)

Version: macOS Sonoma 14.8.7

Vendor release date: May 11, 2026

Published on updatealert.io: Jun 30, 2026

Description: Desktop operating system for Apple Mac devices.