On May 11, 2026, Apple released macOS Sequoia 15.7.7 as a security update for the legacy macOS branch[1][2]. The accompanying advisory lists 45 CVE-identified fixes, addressing a swath of serious flaws across the Kernel, Wi-Fi, and WebKit stacks[1]. The release ships alongside the current macOS Tahoe 26.5, giving Mac users who have not yet moved to the latest branch an equivalent level of patching[2].

Release date, scope, and patch volume

Apple's security release 127116 documents the public availability of macOS Sequoia 15.7.7 on May 11, 2026[1]. AppleInsider characterizes the day's roundup as a sweeping batch covering not only Tahoe 26.5 but also Sequoia 15.7.7, Sonoma 14.8.7, iOS 18.7.9 / iPadOS 18.7.9, iPadOS 17.7.11, iOS 16.7.16, and iOS 15.8.8, with Sequoia positioned as the mainline branch for Mac users who have not yet upgraded to Tahoe 26.5[2].

The release patches 45 CVE-identified issues. By component, Kernel accounts for 9 fixes, Wi-Fi for 2, IOHIDFamily for 2, ImageIO for 2, SceneKit for 2, and mDNSResponder for 2, with additional root-privilege escalation paths closed in StorageKit, PackageKit, and CUPS[1]. AppleInsider notes that "none of the advisories identify the patched vulnerabilities as actively exploited in the wild," so no zero-day fix is part of this round[2].

Kernel and Wi-Fi — root escalation and arbitrary kernel-level code execution

Inside the Kernel, Apple addressed an authorization state-management issue that allowed an app to gain root privileges (CVE-2026-28951), an out-of-bounds write that permitted writing to kernel memory (CVE-2026-28972), a buffer overflow that let a local user trigger unexpected system termination or read kernel memory (CVE-2026-28897), and an integer overflow (CVE-2026-28952), among other high-severity items[1]. On the information-disclosure side, CVE-2026-43654 and CVE-2026-28987 close kernel-state leakage paths, while CVE-2026-28986 corrects a race condition[1]. For Gatekeeper, the file-quarantine bypass involving a maliciously crafted disk image (CVE-2026-28954) is patched in the same round[1].

Wi-Fi receives a fix for an out-of-bounds write that allowed an app to execute arbitrary code with kernel privileges (CVE-2026-28819)[1]. The same fix ships in macOS Tahoe 26.5, and AppleInsider explicitly flags the Wi-Fi flaw as "an out-of-bounds write that allows arbitrary code execution with kernel privileges"[2]. A second Wi-Fi item, CVE-2026-28994, closes a use-after-free that let an attacker in a privileged network position cause a denial-of-service with crafted packets[1]. For the Kernel integer-overflow fix CVE-2026-28952, Apple's credit line specifically reads "Calif.io in collaboration with Claude and Anthropic Research"[1].

Other components — CUPS and PackageKit root paths, ImageIO and mDNSResponder RCE

Root-privilege escalation paths closed in this release include the CUPS directory-path parsing flaw (CVE-2026-28915), the PackageKit permissions issue (CVE-2026-28840), and the StorageKit consistency issue (CVE-2026-28919)[1]. Multiple sandbox-escape vulnerabilities also land in the same update: GPU Drivers (CVE-2026-28923), Icons (CVE-2025-43524), and Installer (CVE-2026-28978)[1].

On the networking side, mDNSResponder receives two fixes: a use-after-free (CVE-2026-43668) that could let a remote attacker cause unexpected system termination or corrupt kernel memory, and an out-of-bounds write (CVE-2026-43666) that enabled a denial-of-service on the local network[1]. File-handling stacks see ImageIO bounds-check fixes (CVE-2026-28977 and CVE-2026-28990) and SceneKit memory-handling fixes (CVE-2026-39870 and CVE-2026-28846)[1]. Privacy items rounded up here include Networking's IP-address tracking issue (CVE-2026-28906), Crash Reporter's installed-app enumeration leak (CVE-2026-28878), and a Sync Services race condition that allowed unauthorized Contacts access (CVE-2026-28924)[1].

Summary

macOS Sequoia 15.7.7 is a security-focused release shipped on the same day as macOS Tahoe 26.5, bundling 45 CVE fixes that cover a Wi-Fi kernel RCE, root-privilege escalations in Kernel, CUPS, PackageKit, and StorageKit, several sandbox escapes, and a Gatekeeper bypass. It targets every Mac still running macOS Sequoia, and users who have not yet moved to Tahoe should install it promptly via System Settings → Software Update.

Source:[1] https://support.apple.com/en-us/127116

Source:[2] https://appleinsider.com/articles/26/05/11/update-your-older-iphone-ipad-or-mac-now-to-get-new-fixes-for-webkit-wi-fi-kernel-flaws

Source:[3] https://support.apple.com/en-us/100100