In the ongoing effort to squash security-related bugs before they can be exploited, Apple has released macOS 26.5.2 Tahoe, iOS 26.5.2 and iPadOS 26.5.2, and Safari 26.5.2 for macOS 15 Sequoia and macOS 14 Sonoma. The security-only updates focus on WebKit and related technologies, providing 23 fixes; the macOS, iOS, and iPadOS updates also address 6 additional vulnerabilities, including several in the kernel. Apple doesn’t say that any have been exploited in the wild.
The strangest aspect of these updates is that the release notes for each open with a statement about current beta releases:
This update delivers security fixes that were first made available in the macOS Tahoe 26.6 beta. This document describes the security content of macOS Tahoe 26.5.2.
This update delivers security fixes that were first made available in the iOS 26.6 and iPadOS 26.6 betas. This document describes the security content of iOS 26.5.2 and iPadOS 26.5.2.
This update delivers security fixes that were first made available in the macOS Tahoe 26.6 beta. This document describes the security content of Safari 26.5.2.
I don’t know what, if anything, to make of the first sentence in each of those introductions, but I’m not aware of Apple using it before. Normally, security release notes start with the “This document describes” line.
Beyond the Kremlinology of the wording change, the security fixes seem sufficiently serious that I recommend updating your Macs, iPhones, and iPads soon. The new versions seem to be working fine for me.
Evidently they had built these security features into the OS 26.6 betas already, but then presumably decided they were important and urgent enough to read them back onto OS 26.5 immediately, rather than waiting for OS 26.6 to go final. Similar, perhaps, to those medical trials where the drug being tested turns out to be so valuable that they call off the trial early and just give it to everyone…
It would be very helpful for many Mac users if Apple would be less secretive about the specific malware & other threats that are being addressed and the nature of the fixes. . . Apple even uses unique monikers that do not correspond with the accepted malware names. It doesn’t help anything and it just looks like Apple is trying to hide something.
Over the years Howard Oakley at The Eclectic Light Company has written about Apple’s penchant for security obfuscation multiple times. Fortunately, Howard has released a number of utilities such as Silent Knight that are very helpful at allowing users to know what is going on under the hood of XProtect, etc. But they can only do so much because the apps are limited in how much info they can glean from the OS.
Apple I am sure is secretive because revealing the nature of the threats would put users who had not yet upgraded at risk. The unwritten rule of threats is to keep them secret for 90 days before the secrets are revealed. This doesn’t always happen, but usually does.
There is a typical embargo period for newly identified threats to give companies time to develop and release a fix so users can install updates. That is not the same as what Apple is doing.
Apple never clearly identifies and describes the threats that the company addresses via updates for MacOS or its built-in anti-malware apps such as XProtect. It’s anti-malware software also does not notify the user of threats it has found and fixed on its devices.
The only indication that users have is whether XProtect is up-to-date. That is tucked away in Systems Settings>General>About then scroll to the bottom and click System Report. In the Software section click Installations, then scroll down to the XProtect updates info. That’s it. . . no other information is provided.
All of the commercial anti-malware utilities that I am aware of identify malware that is found using cyber security nomenclature and indicates whether or not it has been successfully neutralized.
I would not have expected it from a simple security update, but sure enough, after installing 26.5.2 on my M4 Pro 14", all the MS-ish auto tiling stuff under Settings > Desktop & Dock > Windows got turned back on. Argh! Turn. That. ****. Off. [/ChrisRock]
The “Glass Wing” Project: Due to its immense capability to find thousands of software vulnerabilities—which risks exploitation if misused or accessed by foreign nationals—Anthropic initially limited Mythos to a highly vetted group of about 40 trusted corporations (including major U.S. banks and tech rivals).
Adam, the first sentence is not really all that mysterious — and it speaks to the accelerating race between the good guys and the bad guys. As soon as new code is made available, the bad guys analyze it (reverse engineer it) to understand the vulnerabilities that are fixed in order to exploit them. This is the rationale behind your advise to update ASAP (a long time delay between exposure and a published fix puts people at risk). It comes down to a race condition. So — and I think wisely — Apple is (finally) making these security fixes available to their non-beta customers as soon as they are available (and sufficiently tested). I’m a big fan of this change.