Apple macOS Sequoia (15) Update Version macOS Sequoia 15.7.7
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
macOS Sequoia 15.7.7 addresses multiple security issues across APFS, Kernel, Wi-Fi, and other components. The update includes fixes for privilege escalation, sandbox escapes, memory corruption, and information disclosure, with many CVE references.
Update Details
Security
- APFS: buffer overflow could cause unexpected system termination; fixed with improved bounds checking.
CVE-2026-28959 - AppleJPEG: memory corruption when processing malicious media could terminate the app or corrupt memory.
CVE-2026-28956 - Audio: malicious media could terminate the process.
CVE-2026-39869 - CoreMedia: app could access private information.
CVE-2026-28922 - Crash Reporter: privacy issue could allow enumeration of installed apps.
CVE-2026-28878 - CUPS: parsing issue could allow root privileges.
CVE-2026-28915 - FileProvider: race condition could expose sensitive user data.
CVE-2026-43659 - GPU Drivers: logging issue could enable sandbox escape.
CVE-2026-28923 - HFS: buffer overflow could cause system termination or kernel memory write.
CVE-2026-28925 - Icons: access issue could enable sandbox escape.
CVE-2025-43524 - ImageIO: multiple memory safety issues could cause app termination or memory corruption.
CVE-2026-28977,CVE-2026-28990 - Installer: permissions issue could enable sandbox escape.
CVE-2026-28978 - IOHIDFamily: memory corruption and kernel memory layout disclosure issues.
CVE-2026-28992,CVE-2026-28943 - IOKit: use-after-free could cause system termination.
CVE-2026-28969 - Kernel: multiple issues including kernel memory disclosure, Gatekeeper bypass, buffer overflow, integer overflow, protected file system modification, privilege escalation, out-of-bounds write, race condition, and kernel state leakage.
CVE-2026-43654,CVE-2026-28954,CVE-2026-28897,CVE-2026-28952,CVE-2026-28908,CVE-2026-28951,CVE-2026-28972,CVE-2026-28986 - Mail Drafts: Lockdown Mode issue could display remote images when replying to email.
CVE-2026-28987 - mDNSResponder: use-after-free and out-of-bounds write could cause system termination, kernel memory corruption, or local denial of service.
CVE-2026-28929,CVE-2026-43668 - Model I/O: memory corruption and denial-of-service or memory disclosure issues.
CVE-2026-43666,CVE-2026-28940,CVE-2026-28941 - Networking: IP address tracking issue fixed through improved state management.
CVE-2026-28906 - PackageKit: permissions issue could allow root privileges.
CVE-2026-28840 - Quick Look: out-of-bounds write could cause unexpected app termination.
CVE-2026-43656 - SceneKit: memory corruption and remote app termination issues.
CVE-2026-39870,CVE-2026-28846 - Shortcuts: added an additional prompt for user consent to protect user-sensitive data.
CVE-2026-28993 - SMB: buffer overflow could cause unexpected system termination.
CVE-2026-28848 - Spotlight: denial-of-service issue fixed with improved checks.
CVE-2026-28974 - Storage: race condition could expose sensitive user data.
CVE-2026-28996 - StorageKit: consistency issue could allow root privileges.
CVE-2026-28919 - Sync Services: race condition could allow Contacts access without user consent.
CVE-2026-28924 - TV App: path handling issue could expose unprotected user data.
CVE-2026-39871 - Wi-Fi: out-of-bounds write could allow kernel-privileged code execution; use-after-free could enable denial of service.
CVE-2026-28819,CVE-2026-28994 - zlib: information leakage could expose sensitive data when visiting a malicious website.
CVE-2026-28920
Hints
- Applies to macOS Sequoia.
- Apple security documents reference vulnerabilities by CVE-ID when possible.
Product Information
Vendor: Apple
Product: macOS
Product type: Software
Platform: macOS
Variant: Sequoia (15)
Version: macOS Sequoia 15.7.7
Vendor release date: May 11, 2026
Original release notes: View on vendor site
Published on updatealert.io: Jun 30, 2026
Description: Desktop operating system for Apple Mac devices.