On May 11, 2026, Apple released macOS Sonoma 14.8.7 as a security update for its legacy macOS branch[1][2]. The accompanying advisory lists 42 CVE-tracked fixes, sweeping up serious flaws in Kernel, Wi-Fi, mDNSResponder, and other components in a single release[1]. It rolled out the same day as macOS Tahoe 26.5 (the current release) and macOS Sequoia 15.7.7, bringing comparable protection to Macs still on Sonoma[2].

Release date, scope, and patch size

Apple's security release notice 127117 lists the release date for macOS Sonoma 14.8.7 as May 11, 2026[1]. AppleInsider characterized this round as "a large batch of patches that extends to Sequoia 15.7.7, Sonoma 14.8.7, iOS 18.7.9 / iPadOS 18.7.9, iPadOS 17.7.11, iOS 16.7.16, and iOS 15.8.8 in addition to the current release," positioning Sonoma as the legacy branch for Mac users who have not yet moved to Tahoe or Sequoia[2].

The advisory enumerates 42 distinct CVE fixes. By component, Kernel accounts for 9, mDNSResponder for 3, and Wi-Fi, IOHIDFamily, ImageIO, and SceneKit for 2 each, with CUPS, PackageKit, StorageKit, and other root-privilege-escalation fixes among the rest[1]. AppleInsider notes that "none of the advisories include a notation that the issues are known to be actively exploited," meaning there are no zero-day fixes in this batch[2].

Kernel and Wi-Fi — root escalation and arbitrary code execution at kernel level

Within Kernel, the patch list is heavy. CVE-2026-28951 is an authorization-state issue that allowed an app to gain root privileges, CVE-2026-28972 is an out-of-bounds write that permitted kernel-memory writes, CVE-2026-28897 is a buffer overflow letting a local user trigger unexpected system termination or read kernel memory, and CVE-2026-28952 is an integer overflow — each rated at high severity[1]. On the information-leak side, CVE-2026-43654 and CVE-2026-28987 close off kernel-state leakage, while CVE-2026-28986 fixes a race condition[1]. A separate Gatekeeper bypass via a malicious disk image, CVE-2026-28954, was patched in the same round[1].

In Wi-Fi, CVE-2026-28819 — an out-of-bounds write that allowed an app to execute arbitrary code with kernel privileges — was fixed[1]. This is the same fix shipping with macOS Tahoe 26.5 and Sequoia 15.7.7, and AppleInsider warns that the "Wi-Fi vulnerability allowed an out-of-bounds write to execute arbitrary code with kernel privileges"[2]. The second Wi-Fi fix, CVE-2026-28994, closes a use-after-free that let an attacker in a privileged network position cause denial-of-service via crafted Wi-Fi packets[1]. For the Kernel integer-overflow fix CVE-2026-28952, Apple's credit line notes the issue was "found by Calif.io in collaboration with Claude and Anthropic Research"[1].

Elsewhere — root via CUPS and PackageKit, remote flaws in mDNSResponder

Other root-privilege fixes include CUPS CVE-2026-28915 (a directory-path parsing issue), PackageKit CVE-2026-28840 (tighter permissions), and StorageKit CVE-2026-28919 (revised state handling)[1]. Sandbox-escape patches are also present across GPU Drivers (CVE-2026-28923), Icons (CVE-2025-43524), and Installer (CVE-2026-28978)[1].

On the networking side, the mDNSResponder use-after-free CVE-2026-43668 could let a remote attacker trigger unexpected system termination or kernel-memory corruption; CVE-2026-43666 closes an out-of-bounds write that enabled local-network denial-of-service; and CVE-2026-43653 addresses the same DoS class via improved memory handling[1]. File-processing patches include ImageIO bounds-check fixes CVE-2026-28977 and CVE-2026-28990, plus SceneKit memory-corruption fixes CVE-2026-39870 and CVE-2026-28846[1]. On the privacy front, Networking CVE-2026-28906 closed user tracking through IP address, Sync Services CVE-2026-28924 cut off unsanctioned access to Contacts, and Shortcuts CVE-2026-28993 limited access to user-sensitive data[1].

Summary

macOS Sonoma 14.8.7 is a security-focused update for the Sonoma branch, shipped on the same day as the current macOS Tahoe 26.5 and the legacy macOS Sequoia 15.7.7. It rolls up 42 CVEs that close a Wi-Fi kernel RCE, root-privilege escalations across Kernel, CUPS, PackageKit, and StorageKit, multiple sandbox escapes, and a Gatekeeper bypass[1]. The update targets every Mac still running macOS Sonoma; if you are not yet moving to a newer branch, it is best to apply it promptly from System Settings → Software Update.

Source:[1] https://support.apple.com/en-us/127117

Source:[2] https://appleinsider.com/articles/26/05/11/update-your-older-iphone-ipad-or-mac-now-to-get-new-fixes-for-webkit-wi-fi-kernel-flaws

Source:[3] https://support.apple.com/en-us/100100