Jeff Johnson (My apps, PayPal.Me, Mastodon)

Apple 0-dayed Safari on macOS Sequoia and Sonoma

May 13 2026

Update: Apple has now finally released Safari 26.5 for Sonoma and Sequoia. I’m going to take credit for that coincidence. ;-)

Some people have objected to my use of the term 0-day. I’m not sure there is a good term for a situation where a software vendor knowingly fails to patch a vulnerability while simultaneously providing enough public information about the vulnerability for attackers to devise an exploit quickly. Indeed there shouldn’t be a good term for this situation, because it shouldn’t occur!

I’m unaware of any explicit policy, but Apple’s long-standing practice is to release security updates for the latest three major versions of macOS. Currently, those are macOS 26 Tahoe, macOS 15 Sequoia, and macOS 14 Sonoma. On Monday, two days ago, Apple continued that practice by releasing macOS 26.5, 15.7.7, and 14.8.7. Another long-standing practice is to include Safari updates along with the latest major version of macOS but release Safari updates separately for the previous two major versions. Thus, Safari 26.0 was originally included along with macOS 26.0 back in September, and Safari 26.5 was included along with the macOS 26.5 update, whereas Safari 26.0 through 26.4 were separate updates for macOS 14 and 15. Originally, macOS 14.0 shipped with Safari 17.0 and macOS 15.0 with Safari 18.0. You can still run those older versions of Safari, though it’s inadvisable due to unpatched security vulnerabilities.

You can see on the Apple security releases support page that Safari 26.4 was released for Sequoia and Sonoma on March 24, the same day as macOS Tahoe 26.4. Inexplicably, however, Apple has still failed to release Safari 26.5 for Sequoia and Sonoma. If you look at the list of WebKit vulnerabilities in the security content of macOS Tahoe 26.5, those are now 0-day vulnerabilities in Safari 26.4 on Sequoia and Sonoma. Any malware author in the world can read the description of those vulnerabilities, compare the WebKit binaries on macOS 26.5 to the WebKit binaries on macOS 26.4, and reverse engineer the fixes, which would allow them to develop exploits for the vulnerabilities. The reason that software vendors standardly update all vulnerable software on the same day is to avoid this exact situation, when there’s a significant window of time for malware authors to develop attacks on vulnerable, unpatchable systems.

The notoriously secretive Apple has of course not commented on the absence of a Safari 26.5 update. Perhaps the news media could ask Apple to comment. You might speculate that Safari 26.5 was not yet ready on Monday, for some technical reason. This would be a terrible excuse, though, because Apple determines the release dates of all of its software and could have delayed the other updates until everything was ready, thereby avoiding the 0-days. Moreover, Apple did release WebKit fixes on Monday in iOS 18.7.9 and iPadOS 18.7.9. How were those Safari updates ready, but the Safari updates for macOS Sequoia and Sonoma were not? (Unlike with macOS, Safari updates are always included with iOS, regardless of whether it’s the latest major version of iOS.)

Here’s the catch, as noted by Michael Tsai:

After a brief reprieve, Apple seems to have gone back to the policy of iOS 18.7.3, where you can only get iOS 18.7.9 if your phone is not capable of running iOS 26.

In other words, Apple’s security updates on iOS are passive-aggressive, forcing you to update from iOS 18 to iOS 26 on pain of affliction with 0-day vulnerabilities. Cynically, we might wonder whether Apple is withholding Safari 26.5 on macOS for the same reason, to “encourage” those of us who hate Liquid Glass to install macOS Tahoe anyway. We’ve already seen how Apple tricks users into installing Tahoe.

Alternatively, maybe Apple wants us to switch from Safari to Chrome or Firefox?

Jeff Johnson (My apps, PayPal.Me, Mastodon)