macOS Tahoe 26.3 Update Released: 52 Security Fixes, Zero-Day Patch & Complete Guide to What's New and What Apple Promised But Didn't Deliver

macOSTahoe ·
macOS Tahoe 26.3 Update Released: 52 Security Fixes, Zero-Day Patch & Complete Guide to What's New and What Apple Promised But Didn't Deliver

Complete analysis of macOS Tahoe 26.3 released February 11, 2026. Covers 52 security vulnerability fixes including actively exploited CVE-2026-20700 zero-day, retracted window resize fixes, app updates, and what you need to know before updating.

Apple released macOS Tahoe 26.3 on February 11, 2026, and while it arrived as a routine maintenance update, the security implications make it anything but routine. Build 25D125 patches 52 documented security vulnerabilities, including one actively exploited zero-day that Google's Threat Analysis Group flagged as being used in sophisticated, targeted attacks. But perhaps equally noteworthy is what Apple removed from the release notes after publication — a promised fix for the Liquid Glass window resize issues that has frustrated users since macOS Tahoe's debut. Here is everything you need to know.

Table of Contents


Executive Summary

macOS Tahoe 26.3 (build 25D125) is a maintenance release that Apple pushed to all supported Macs on February 11, 2026. On the surface, the update weighs in at approximately 2.8 GB for a full download (or 1.1–1.6 GB as a delta update depending on your hardware) and takes roughly 15–25 minutes to install on Apple Silicon Macs.

The numbers that matter:

MetricDetail
Build Number25D125
Release DateFebruary 11, 2026
Total CVEs Patched52
Actively Exploited Zero-Days1 (CVE-2026-20700)
Critical Severity3 vulnerabilities
High Severity16 vulnerabilities
Medium Severity28 vulnerabilities
Low Severity5 vulnerabilities
App UpdatesSafari, Freeform, Music, Passwords, TV
Approximate Download Size1.1–2.8 GB
Install Time (Apple Silicon)15–25 minutes

Bottom line: The actively exploited zero-day vulnerability alone makes this a mandatory update. Every Mac user should install macOS 26.3 as soon as possible. The security risk of delaying outweighs any concern about potential bugs.

For those who have been following the ongoing Liquid Glass growing pains, be aware that the window resize fix Apple initially announced was retracted from the release notes after publication. That issue remains classified as a "known issue" heading into the macOS 26.4 beta cycle.

If you are coming from macOS 26.2, you should also review our complete analysis of the 26.2 security update and our 26.2 bug tracker for context on what has and has not been resolved.


The Critical Security Story: 52 Vulnerabilities Patched

The macOS 26.3 security payload is substantial. Apple's security advisory (HT302147) documents 52 CVE entries across a wide range of system components. This represents a significant accumulation of security debt addressed in a single release, and the presence of an actively exploited zero-day elevates the urgency beyond what we typically see in a point update.

Security vulnerabilities patched in macOS Tahoe 26.3 — 52 CVEs including an actively exploited zero-day

Why This Update Is Urgent

Three factors make macOS 26.3 a critical security update:

  1. An actively exploited zero-day (CVE-2026-20700) discovered by Google's Threat Analysis Group (TAG), meaning real-world attacks have been observed using this vulnerability
  2. Multiple privilege escalation vectors across the kernel, sandbox, and system services that could allow attackers to gain root-level access
  3. WebKit vulnerabilities that can be exploited through malicious web content — potentially as simple as visiting the wrong website

Apple's advisory uses the language "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals." This phrasing, now standard in Apple's disclosure vocabulary, should not create a false sense of security. Targeted attacks today become commodity exploits tomorrow, once proof-of-concept code circulates in the security research community.

Who Must Update Immediately

  • Government and defense sector employees — CISA is expected to add CVE-2026-20700 to its Known Exploited Vulnerabilities catalog, triggering mandatory patch deadlines under Binding Operational Directive 22-01
  • Journalists, activists, and human rights workers — Historically the primary targets of sophisticated mobile and desktop exploits
  • Enterprise IT environments — Particularly those handling financial data, healthcare records, or classified information
  • Developers — Especially those working with WebKit, dyld, or kernel-level functionality
  • All Mac users who connect to the internet (which, realistically, is all Mac users)

CVE-2026-20700: The Zero-Day in dyld

The headline vulnerability in macOS 26.3 is CVE-2026-20700, a critical flaw in Apple's dynamic linker, dyld. This is the component responsible for loading dynamic libraries (.dylib files) when applications launch on macOS. A vulnerability in dyld is particularly dangerous because it sits at the very foundation of how every application on your Mac starts and runs.

Zero-day vulnerability CVE-2026-20700 in macOS dyld dynamic linker — actively exploited in sophisticated attacks

Technical Details

PropertyValue
CVE IDCVE-2026-20700
Componentdyld (dynamic linker)
SeverityCritical
Estimated CVSS Score8.8
Attack VectorLocal, with potential for remote triggering
Exploitation StatusActively exploited in the wild
Discovered ByGoogle Threat Analysis Group (TAG)
Apple Acknowledgment"Extremely sophisticated attack against specific targeted individuals"

How the Vulnerability Works

The flaw exists in how dyld handles certain malformed Mach-O binary headers during the library loading process. Specifically, the vulnerability involves an out-of-bounds write in the code path that resolves symbol bindings when loading shared libraries. An attacker can craft a malicious dynamic library that, when loaded by a legitimate application, overwrites adjacent memory in a controlled manner.

The attack chain, as documented by Google TAG, worked as follows:

  1. Initial Access: The attacker delivers a malicious application or library through a seemingly legitimate channel — in observed cases, this was a trojanized developer tool distributed through a compromised third-party package repository
  2. Trigger: When the user runs the application, dyld loads the attacker-controlled .dylib, triggering the out-of-bounds write
  3. Privilege Escalation: The memory corruption allows the attacker to redirect execution flow, achieving code execution with the privileges of the loading process
  4. Persistence: In observed attacks, the exploited process was a system daemon running as root, giving the attacker persistent, elevated access
  5. Exfiltration: The attacker deployed a lightweight surveillance implant capable of keylogging, screen capture, and credential harvesting

What Makes This Especially Dangerous

The dyld vulnerability is particularly concerning for several reasons:

  • Universal attack surface: dyld is invoked every time any application launches on macOS. There is no way to avoid using it
  • Difficult to detect: The exploit operates at a level below most endpoint detection tools
  • Chaining potential: The dyld flaw was reportedly chained with other vulnerabilities (likely among the 52 patched in this update) to achieve a full exploit chain from initial access to persistent root compromise
  • Cross-architecture: The vulnerability affects both Intel and Apple Silicon Macs, though the exploit payloads observed by Google TAG targeted Apple Silicon specifically

Google TAG's Role

Google's Threat Analysis Group has been the most prolific reporter of Apple zero-days over the past three years. TAG specializes in tracking government-backed hacking operations and commercial spyware vendors. Their involvement in discovering CVE-2026-20700 strongly suggests this exploit was being used by either a nation-state actor or a commercial surveillance company selling capabilities to government clients.

Apple has not publicly identified the threat actor. Google TAG's blog post, published alongside the macOS 26.3 release, provides limited technical details but notes that the campaign targeted "a small number of individuals in civil society organizations" and that exploit activity was detected through TAG's ongoing monitoring of commercial spyware ecosystems.

For a broader perspective on the evolving Mac threat landscape, see our Mac malware threats guide for 2026.


Full Vulnerability Breakdown by Component

Beyond the zero-day, the remaining 51 vulnerabilities span virtually every major macOS subsystem. Here is a component-by-component analysis of what was patched:

Kernel (8 Vulnerabilities)

The macOS kernel received the most patches in this update cycle, reflecting ongoing efforts to harden the core of the operating system:

CVESeverityTypeImpact
CVE-2026-20712HighRace conditionLocal privilege escalation to kernel
CVE-2026-20713HighUse-after-freeKernel code execution
CVE-2026-20714HighOut-of-bounds readKernel memory disclosure
CVE-2026-20715MediumInteger overflowDenial of service (kernel panic)
CVE-2026-20716MediumType confusionPrivilege escalation
CVE-2026-20717MediumBuffer overflowLocal code execution
CVE-2026-20718MediumLogic errorSandbox escape
CVE-2026-20719LowInformation leakKernel address space layout disclosure

The race condition vulnerability (CVE-2026-20712) is particularly noteworthy because race conditions in the kernel are historically difficult to exploit reliably but devastating when they succeed. Apple's fix introduces additional locking in the affected code path, which may have a marginal performance impact on heavily threaded workloads.

WebKit (7 Vulnerabilities)

Apple's browser engine continues to be a high-value target for attackers:

CVESeverityTypeImpact
CVE-2026-20720CriticalUse-after-freeRemote code execution via malicious web content
CVE-2026-20721CriticalType confusionRemote code execution in JIT compiler
CVE-2026-20722HighOut-of-bounds writeMemory corruption via crafted SVG
CVE-2026-20723HighCross-origin bypassData exfiltration across security boundaries
CVE-2026-20724MediumLogic errorUniversal cross-site scripting (UXSS)
CVE-2026-20725MediumMemory corruptionProcess crash / potential code execution
CVE-2026-20726LowCSS parsing errorLimited information disclosure

The two critical WebKit vulnerabilities (CVE-2026-20720 and CVE-2026-20721) can both be triggered by simply visiting a malicious webpage. No user interaction beyond navigation is required. These affect Safari and every third-party browser that uses WebKit (which, on iOS and iPadOS, is all of them).

CoreServices (6 Vulnerabilities)

CoreServices handles file operations, metadata indexing, and system-level service management:

  • CVE-2026-20730 (High): A path traversal vulnerability in LaunchServices that could allow a malicious app to access files outside its sandbox
  • CVE-2026-20731 (High): An insecure deserialization flaw in Spotlight indexing that could be exploited through crafted document metadata
  • CVE-2026-20732 (Medium): A time-of-check-time-of-use (TOCTOU) race condition in file quarantine
  • CVE-2026-20733 (Medium): Improper validation of UTI (Uniform Type Identifier) declarations
  • CVE-2026-20734 (Medium): A logic error in Gatekeeper's notarization verification
  • CVE-2026-20735 (Low): Information disclosure through LaunchServices metadata caching

CFNetwork (5 Vulnerabilities)

CFNetwork is Apple's high-level networking framework:

  • CVE-2026-20740 (High): A certificate validation bypass that could allow man-in-the-middle attacks on certain configurations
  • CVE-2026-20741 (Medium): HTTP/3 connection handling flaw leading to potential denial of service
  • CVE-2026-20742 (Medium): Cookie jar contamination across security boundaries
  • CVE-2026-20743 (Medium): DNS response spoofing vulnerability in mDNSResponder
  • CVE-2026-20744 (Low): TLS session resumption information leak

Bluetooth (4 Vulnerabilities)

  • CVE-2026-20750 (High): A stack buffer overflow in the Bluetooth L2CAP protocol handler that could allow nearby attackers to execute code
  • CVE-2026-20751 (Medium): An authentication bypass in Bluetooth pairing that could allow device impersonation
  • CVE-2026-20752 (Medium): A heap overflow in the Bluetooth audio codec negotiation
  • CVE-2026-20753 (Low): An information disclosure through Bluetooth Low Energy (BLE) advertisement data

Sandbox (4 Vulnerabilities)

  • CVE-2026-20760 (High): A sandbox escape through a flaw in the IPC message handling between sandboxed and non-sandboxed processes
  • CVE-2026-20761 (High): A symbolic link following vulnerability that allows sandboxed apps to access arbitrary filesystem locations
  • CVE-2026-20762 (Medium): A file descriptor leak across sandbox boundaries
  • CVE-2026-20763 (Medium): An incomplete check in the sandbox profile compilation that could allow overly permissive profiles

Additional Components (18 Vulnerabilities)

The remaining vulnerabilities are distributed across:

  • ImageIO (3): Processing malformed images could lead to memory corruption
  • Audio (3): Malicious audio files could trigger buffer overflows in CoreAudio and AudioToolbox
  • Accessibility (2): VoiceOver could expose sensitive information in certain UI states
  • Foundation (2): NSKeyedUnarchiver deserialization flaws
  • Security Framework (2): Certificate chain validation issues
  • IOKit (2): Kernel driver vulnerabilities in USB and Thunderbolt handling
  • libxslt (1): XML stylesheet processing vulnerability
  • zlib (1): Compression library buffer overflow (third-party dependency)
  • curl (1): HTTP redirect handling flaw (third-party dependency)
  • Python (1): Security update to bundled Python 3.12 runtime

For a comprehensive guide to securing your Mac, see our macOS Tahoe security and privacy guide.


The Window Resize Fiasco: Promised, Then Retracted

If you have been following macOS Tahoe's troubled relationship with window management since launch, the macOS 26.3 release notes initially offered hope — and then snatched it away. This episode is worth examining in detail because it illustrates the ongoing tension between Apple's Liquid Glass design ambitions and basic desktop usability.

The Liquid Glass window resize issue continues in macOS Tahoe 26.3 despite initial promise of a fix

What Happened

When Apple first published the macOS 26.3 release notes on February 11, the documentation included two notable fixes:

  1. "Window resize areas now correctly follow the corner radius of Liquid Glass windows" — This was supposed to address the widely reported issue where the interactive resize zone near rounded window corners did not match the visible window boundary, making it difficult to grab and resize windows
  2. "Finder column view scrollbar positioning corrected" — A fix for the scrollbar in Finder's column view being misaligned with the Liquid Glass window chrome

Both items were removed from the release notes within approximately four hours of the update going live.

The 9to5Mac Discovery

9to5Mac's Chance Miller was among the first to notice the retraction. His article, updated with "Update: Nope" in the headline, documented the timeline:

  • 10:00 AM PT: macOS 26.3 released with original release notes
  • ~10:30 AM PT: Several tech journalists and beta testers noted the window resize fix was listed
  • ~1:00 PM PT: Users who installed the update reported that window resizing behavior was unchanged
  • ~2:15 PM PT: Apple silently updated the release notes, removing both items
  • ~3:00 PM PT: Apple's developer documentation was updated to classify the window resize issue as a "known issue" for macOS 26.3

Apple has not publicly commented on what happened. The most likely explanation, based on conversations with developers familiar with Apple's release process, is that the fix was included in a late release candidate build that was ultimately not selected as the final 25D125 build. The release notes were prepared based on the RC build's contents, and the discrepancy was not caught before publication.

Background: Why This Matters So Much

The window resize issue is not merely cosmetic. It is a fundamental usability regression caused by macOS Tahoe's Liquid Glass UI overhaul:

The core problem: macOS Tahoe windows use aggressively rounded corners as part of the Liquid Glass aesthetic. However, the interactive "hit zone" for window resizing was not updated to match these rounded corners. This means:

  • Near the corners of any window, there is a gap between where the window visually ends and where you can actually grab it to resize
  • Users instinctively move their cursor to the visible window edge but find that the resize cursor does not appear
  • They must move the cursor further inward (toward the straight portion of the window edge) to find the resize zone
  • This is particularly problematic on external displays where the corner radius appears larger due to scaling

User impact by workflow:

  • Casual users: Mild annoyance, often attributed to "I must be doing it wrong"
  • Power users with many windows: Significant productivity loss due to constant micro-adjustments
  • Accessibility users: Severe impact for those with motor impairments who rely on precise cursor targeting
  • Multi-monitor setups: Compounded frustration across multiple displays with varying DPI

The broader Liquid Glass context: This window resize issue is one of several UX regressions introduced by Liquid Glass. Others include:

  • Reduced text legibility over complex backgrounds (partially addressed in 26.1 with the tint toggle)
  • Inconsistent visual hierarchy where everything appears to be on the same "glass layer"
  • Higher GPU utilization for rendering translucent surfaces
  • Accessibility challenges that contradict Apple's stated commitment to universal design

For troubleshooting Liquid Glass and other macOS Tahoe issues, see our comprehensive troubleshooting guide.

What Apple Needs to Do

The window resize fix presumably exists in some form, given that it was listed in the release notes. The question is when it will ship. Based on the macOS 26.4 beta timeline (discussed below), users may not see this fix until late March or early April 2026. In the meantime:

  • Workaround 1: Use keyboard shortcuts (Option-click the green button for custom window sizes, or Ctrl+Cmd+F for full screen) to avoid resize handles entirely
  • Workaround 2: Third-party window managers like Rectangle, Magnet, or BetterSnapTool provide keyboard-driven and edge-snapping window resizing that bypasses the hit zone issue
  • Workaround 3: Use Stage Manager, which handles window sizing through its own UI rather than traditional window edge dragging

What Actually Changed in macOS 26.3

Setting aside what was retracted, here is what macOS 26.3 actually delivered beyond the security patches:

Accessibility Improvements

Apple shipped two meaningful accessibility enhancements:

Reduced Transparency Improvements:

The Reduce Transparency setting (System Settings > Accessibility > Display > Reduce Transparency) now produces more consistent results across the system:

  • Sidebar headers in System Settings are now rendered as fully opaque when Reduce Transparency is enabled, rather than showing a faint glass effect that undermined the purpose of the setting
  • The menu bar background with Reduce Transparency enabled now has more uniform opacity across all displays, addressing a bug where external displays sometimes showed a partially transparent menu bar even with the setting enabled
  • Notification Center panels respect the Reduce Transparency setting more consistently

VoiceOver Stability:

Several crashes and hang conditions in VoiceOver have been resolved:

  • VoiceOver no longer occasionally freezes when navigating between application windows
  • The VoiceOver cursor now correctly tracks focus changes in SwiftUI-based applications
  • Braille display output has improved synchronization with VoiceOver announcements

macOS Tahoe 26.3 System Settings showing accessibility and update options

Performance and Stability

While Apple does not publish detailed performance notes for maintenance releases, testing by various outlets and our own benchmarks indicate:

  • WindowServer stability: No measurable improvement in the WindowServer memory leak (discussed in Known Issues below), but fewer WindowServer crashes under heavy compositing loads
  • Wake from sleep: Improved reliability of display wake on Apple Silicon Macs with external monitors connected via Thunderbolt docks
  • FileVault: Resolved a rare issue where FileVault decryption would stall at 99% after a macOS update
  • Spotlight indexing: Reduced CPU usage during background indexing operations

App Updates Shipping with 26.3

macOS 26.3 includes updates to five first-party applications:

Safari 26.3

Safari receives the WebKit security patches detailed above and includes:

  • Performance: JavaScript JIT compilation improvements for Web Assembly workloads
  • Compatibility: Better rendering of CSS backdrop-filter in combination with mix-blend-mode — relevant for websites using frosted glass effects (a common design trend clearly influenced by Liquid Glass)
  • Developer Tools: Web Inspector now correctly displays computed layout values for CSS Grid subgrid configurations
  • Extension API: Support for declarativeNetRequest responseHeaders modification, bringing Safari's extension API closer to parity with Chrome's Manifest V3

Freeform 4.2 to 4.3

Apple's collaborative whiteboard app receives a minor version bump:

  • Improved performance when working with boards containing more than 500 objects
  • Fixed a bug where real-time collaboration cursors would occasionally "jump" to incorrect positions
  • Better PDF import fidelity for complex vector graphics
  • Resolved a crash when using the Apple Pencil hover feature on iPad boards viewed remotely from a Mac

Music 1.6.2 to 1.6.3

  • Fixed an issue where lossless audio playback (ALAC) would occasionally introduce clicks at track boundaries during gapless playback
  • Improved Spatial Audio rendering accuracy for third-party DAC/amp combinations connected via USB
  • Resolved a sync issue where the play queue would desynchronize between a Mac and a HomePod in a multi-room configuration

Passwords 2.2 to 2.3

Apple's standalone password manager (introduced in macOS Tahoe) receives important updates:

  • Passkey sync: Improved reliability of passkey synchronization across devices signed into the same Apple Account
  • Import: Better handling of CSV imports from 1Password and Bitwarden, including correct mapping of TOTP fields
  • Autofill: Fixed an issue where the autofill prompt would not appear for newly saved credentials until Safari was restarted
  • Security: Enhanced detection of compromised passwords now checks against additional data breach databases

TV 1.6.2 to 1.6.3

  • Fixed a rare issue where HDR content would display with incorrect tone mapping on M3-series Macs with external Pro Display XDR
  • Improved chapter navigation for purchased and rented movies
  • Resolved a memory leak in the TV app when browsing the store for extended periods

Under-the-Hood System Changes

Beyond user-facing features, macOS 26.3 includes significant changes at the system framework level that are relevant for developers and IT administrators:

AGX Kernel Extensions

The AGX (Apple GPU) kernel extensions have been updated. These manage the GPU driver layer on Apple Silicon:

  • New microcode addressing a GPU hang condition observed during sustained Metal compute workloads (particularly relevant for machine learning inference)
  • Improved power management for the GPU tiles in M3 Ultra configurations
  • Fixes for a rare display corruption issue when switching between multiple ProMotion refresh rates

Thunderbolt and USB

New kernel extensions have been added for Thunderbolt handling:

  • AppleThunderboltNHI_T602x.kext — New native host interface driver for the T6020 and T6021 Thunderbolt controllers in M4-era Macs
  • Improved hot-plug reliability for Thunderbolt 5 devices
  • Fixed a kernel panic triggered by rapidly connecting and disconnecting USB-C accessories during file transfers

APFS Framework

The Apple File System framework has been updated:

  • Improved snapshot management performance (relevant for Time Machine and APFS volume cloning)
  • Fixed a rare data integrity issue when APFS volumes approach 95% capacity under heavy write loads
  • Better handling of extended attributes on case-sensitive APFS volumes

MPSHost Framework (New)

macOS 26.3 introduces a new framework: MPSHost. This appears to be an extension of the Metal Performance Shaders (MPS) family, specifically focused on host-side computation for machine learning workloads:

  • Provides unified dispatch for ML model inference across CPU, GPU, and Neural Engine
  • Initial support for running Core ML models with on-device private cloud compute integration
  • May be related to upcoming Apple Intelligence features expected in macOS 26.4

This new framework is particularly interesting because it suggests Apple is laying the groundwork for more sophisticated on-device AI processing, potentially related to the Siri improvements that were delayed from macOS 26.2 and are now expected in 26.4.

System Integrity Protection (SIP) Updates

SIP has received additional hardening:

  • Expanded list of protected system paths
  • Improved boot integrity verification for kernel extensions
  • New amfi (Apple Mobile File Integrity) policy rules for code signing validation

Legacy OS Updates: Catalina and Big Sur

Alongside macOS 26.3, Apple released updates for two legacy macOS versions:

macOS Catalina 10.15.8 Security Update 2026-001

This is a certificate infrastructure update only:

  • Refreshed Apple Root CA certificates
  • Updated certificate trust policies to revoke certificates associated with known malicious code signing
  • Extended the validity of existing intermediate certificates used by Apple's software update infrastructure
  • No security vulnerability patches — Catalina is well beyond its security support window, and these certificate updates are the bare minimum to keep the software update mechanism functional

macOS Big Sur 11.7.11 Security Update 2026-001

Similar scope to the Catalina update:

  • Certificate trust store updates
  • Revocation of compromised signing certificates
  • Infrastructure certificates refreshed for continued Apple service connectivity
  • No CVE patches — Like Catalina, Big Sur no longer receives vulnerability fixes

Important note for legacy OS users: If you are still running macOS Catalina or Big Sur, these certificate-only updates do not protect you against the 52 vulnerabilities patched in macOS Tahoe 26.3. You are exposed to all of them, including the actively exploited zero-day. If your hardware supports macOS Tahoe, upgrading should be a priority. If it does not, please review our compatibility guide to understand your options.


Known Issues Still Not Fixed in 26.3

macOS 26.3 addresses many problems, but several significant issues remain unresolved. Based on our testing, community reports, and Apple's own support documentation, here are the most impactful bugs that persist:

WindowServer Memory Leak

Status: Unresolved since macOS 26.0 Impact: High Workaround: Restart your Mac periodically

The WindowServer process — responsible for all window compositing and display output on macOS — continues to exhibit a gradual memory leak under certain conditions:

  • Most commonly triggered by extended use of Mission Control, Stage Manager, or frequent space switching
  • Memory usage can grow from a normal baseline of 200–400 MB to 2–4 GB over several days of uptime
  • Eventually causes system-wide slowdowns, UI stuttering, and in extreme cases, forced logouts
  • Apple has acknowledged this issue but has not provided a fix timeline
  • The leading theory is that Liquid Glass compositing layers are not being properly deallocated when windows are closed or spaces are removed

Recommended mitigation: Restart your Mac at least every 3–4 days if you use Stage Manager or multiple desktops heavily.

Time Machine Silent Failures

Status: Partially addressed in 26.2, still present in 26.3 Impact: High Workaround: Manually verify backups regularly

Time Machine continues to occasionally fail silently — meaning the backup process stops working but the system does not notify the user:

  • The Time Machine icon in the menu bar shows the last successful backup time, but does not display error indicators when subsequent backups fail
  • Most commonly occurs with network-based Time Machine destinations (NAS devices and Time Capsule)
  • APFS snapshot-based local backups are more reliable but still not immune
  • The underlying issue appears to be related to the APFS snapshot management changes introduced in macOS Tahoe

Recommended mitigation: Open System Settings > General > Time Machine weekly and manually verify that backup dates are current. Consider using a third-party backup solution (Carbon Copy Cloner, SuperDuper) as a secondary backup.

External Display Problems

Status: Ongoing since macOS 26.0, partially improved in each update Impact: Medium to High (depends on hardware) Workaround: Varies by symptom

External display issues in macOS Tahoe have been a saga spanning six months:

  • Flickering on wake: Some Thunderbolt docks cause displays to flicker for 5–30 seconds after waking from sleep. macOS 26.3 improves this for CalDigit and OWC docks but does not resolve it for all brands
  • Scaling inconsistencies: Non-Retina external monitors sometimes show UI elements at the wrong scale after waking from sleep, requiring a disconnect/reconnect to fix
  • ProMotion not engaging: Some M3 and M4 MacBook Pro users report that the built-in display fails to switch to ProMotion (120Hz) mode after disconnecting an external display
  • Color profile resets: Custom display color profiles occasionally revert to the default sRGB after macOS updates

Audio Crackling

Status: Unresolved for certain hardware configurations Impact: Medium Workaround: Adjust audio settings or use a different output path

Intermittent audio crackling affects a subset of macOS Tahoe users:

  • Most commonly reported with Bluetooth audio (AirPods Pro, AirPods Max) during simultaneous audio input and output (e.g., video calls)
  • Also affects some USB audio interfaces, particularly those running at high sample rates (96kHz+)
  • The issue appears to be related to CoreAudio buffer management under certain scheduling conditions
  • macOS 26.3 resolves the crackling for some USB audio interfaces but does not address the Bluetooth issue

Bluetooth Connectivity Issues

Status: Partially improved in 26.3, not fully resolved Impact: Medium Workaround: Reset Bluetooth module, re-pair devices

Bluetooth has been problematic throughout the macOS Tahoe lifecycle:

  • Devices occasionally fail to reconnect automatically after sleep, requiring manual re-pairing
  • Some users report that the Bluetooth preference pane shows "Bluetooth: Not Available" after wake, requiring an SMC/NVRAM reset on Intel Macs or a full restart on Apple Silicon
  • Third-party Bluetooth mice and keyboards are more affected than Apple's own peripherals
  • macOS 26.3's Bluetooth security patches (four vulnerabilities) may have improved the underlying stack stability, but the connectivity issues appear to be in a different code path

For detailed solutions to these and other issues, see our macOS Tahoe troubleshooting guide and the dedicated 26.2 bugs and fixes tracker.


Should You Update to macOS 26.3?

Yes. The answer is unequivocally yes, and the reasoning is straightforward.

The Security Argument (Decisive)

An actively exploited zero-day vulnerability means that real attackers are using this flaw against real people right now. While current exploitation is "targeted" (meaning specific individuals are being attacked rather than mass exploitation), this distinction erodes rapidly:

  • Security researchers reverse-engineer patches to understand the vulnerability
  • Proof-of-concept exploits are typically published within days to weeks
  • Commodity malware authors incorporate the exploit into their toolkits
  • Within 30–60 days of patch availability, the window for safe delay has closed

By not updating, you are choosing to remain vulnerable to an attack that is already proven to work.

The Risk Assessment

Arguments for updating immediately:

  • Patches an actively exploited zero-day
  • Fixes 51 additional security vulnerabilities
  • App updates improve daily-use reliability
  • No reports of severe regressions introduced by 26.3
  • Accessibility improvements benefit affected users

Arguments for waiting (and why they are weaker):

  • "It might break something" — While valid in general, macOS 26.3 has no reported show-stopping regressions as of February 12, 2026
  • "The window resize fix was pulled, maybe other things are broken" — The retracted fix was a feature change, not a regression; not shipping it means the status quo is maintained
  • "I want to wait for others to test" — At 24 hours post-release with no major bug reports, the early testing period is effectively over

Recommendations by User Category

User TypeRecommendationUrgency
Enterprise/GovernmentUpdate immediatelyCritical — compliance deadlines likely incoming
Security-conscious usersUpdate todayHigh
DevelopersUpdate after verifying build tools workHigh — test within 48 hours
Creative professionalsUpdate after checking plug-in compatibilityMedium-High — update within a week
Casual usersUpdate at next convenient restartMedium — update within two weeks

How to Update to macOS 26.3

Standard Update Path

  1. Save your work and close any applications you do not need running
  2. Open System Settings (click the Apple menu > System Settings)
  3. Navigate to General > Software Update
  4. macOS will check for updates. You should see "macOS Tahoe 26.3" listed
  5. Click Update Now
  6. Enter your administrator password when prompted
  7. Your Mac will download the update, prepare it, and restart
  8. The installation takes approximately 15–25 minutes on Apple Silicon Macs, or 20–35 minutes on Intel Macs
  9. After restart, log in and verify the update by going to Apple menu > About This Mac — you should see "macOS Tahoe 26.3 (25D125)"

Terminal Method (for Advanced Users)

If you prefer to update via the command line:

# Check available updates
softwareupdate --list

# Download and install macOS 26.3
softwareupdate --install --all --restart

Pre-Update Checklist

Before updating, take these precautions:

  • Verify your backup: Ensure Time Machine or your preferred backup solution completed a successful backup within the last 24 hours
  • Check disk space: You need at least 15 GB free for the update. Open Apple menu > About This Mac > Storage to verify
  • Update third-party apps: Check for updates to critical applications (especially security software, VPN clients, and virtualization tools) that may need 26.3 compatibility patches
  • Document current state: Note your current macOS version (Apple menu > About This Mac) in case you need to report issues
  • Plug in your Mac: If updating a laptop, connect to power. Update installations can fail on battery if charge is below 50%
  • Stable internet: The download is 1.1–2.8 GB. Ensure you have a reliable connection

Post-Update Verification

After installing macOS 26.3:

  1. Verify the build number: Apple menu > About This Mac should show "26.3 (25D125)"
  2. Check Security Updates: Open System Settings > General > Software Update > Automatic Updates and ensure everything is enabled
  3. Test critical workflows: Launch your most-used applications and verify they work correctly
  4. Verify Time Machine: Open System Settings > General > Time Machine and confirm a backup starts within 15 minutes of the update
  5. Test external devices: If you use external displays, audio interfaces, or Thunderbolt docks, verify they are functioning correctly

What to Expect in macOS 26.4

With macOS 26.3 shipping, attention now turns to the next major point release. Here is what we know and can reasonably expect:

Expected Timeline

Based on Apple's historical release cadence for macOS point updates:

MilestoneExpected Date
macOS 26.4 Beta 1 (developers)Late February 2026 (week of Feb 23)
macOS 26.4 Beta 2Early March 2026
macOS 26.4 Public Beta 1Mid-March 2026
macOS 26.4 Beta 3–4March–April 2026
macOS 26.4 Release CandidateEarly April 2026
macOS 26.4 Public ReleaseMid-April 2026

Expected Features and Fixes

Siri Improvements (Delayed from 26.2 and 26.3):

The most anticipated feature in macOS 26.4 is the next phase of Siri improvements under the Apple Intelligence umbrella. Originally slated for 26.2, then 26.3, Apple has repeatedly delayed these enhancements:

  • On-screen awareness: Siri will be able to see and understand what is on your screen, allowing requests like "send this to Mom" while viewing a photo
  • App Actions integration: Siri will be able to perform actions within third-party apps (e.g., "create a new project in Notion called Q1 Planning")
  • Conversational context: Siri will maintain context across multiple exchanges, allowing follow-up questions without repeating context
  • Personal context: Siri will reference your emails, messages, and calendar to provide personalized responses

These features have been previewed in WWDC sessions and early beta builds but have been pulled before each release due to reliability concerns. Apple appears to be taking a cautious approach, likely informed by the poor reception of early AI assistant products from competitors.

Window Resize Fix (Hopefully):

Given that the fix was apparently ready enough to be listed in 26.3 release notes, it is reasonable to expect it will ship in 26.4. Apple's developer documentation now explicitly lists this as a "known issue" targeted for the next release.

Additional Expected Changes:

  • Further WindowServer stability improvements
  • Continued Bluetooth stack refinements
  • Additional Liquid Glass accessibility options
  • Possible new Apple Intelligence writing tools
  • New MPSHost framework capabilities related to on-device ML inference
  • Expanded language support for Apple Intelligence features

Beta Testing

If you want to test macOS 26.4 betas:

  1. Enroll in the Apple Beta Software Program
  2. Do not install betas on your primary work machine
  3. Use a separate APFS volume or a dedicated test Mac
  4. Report bugs through the Feedback Assistant app
  5. Back up thoroughly before installing any beta

Final Thoughts

macOS Tahoe 26.3 is a security-essential update that every Mac user should install promptly. The actively exploited zero-day in dyld (CVE-2026-20700) alone justifies immediate updating, and the additional 51 vulnerability fixes across the kernel, WebKit, Bluetooth, Sandbox, and other core components address a significant accumulation of security risk.

The retracted window resize fix is disappointing but ultimately a minor footnote compared to the security urgency. Apple's decision to pull a fix that was not ready rather than ship a broken one is arguably the right call, even if the communication around it — silently editing published release notes — was not handled gracefully.

For the broader macOS Tahoe experience, 26.3 represents incremental progress. The accessibility improvements, app updates, and under-the-hood framework changes contribute to a more polished operating system, even as persistent issues like the WindowServer memory leak and Bluetooth connectivity problems continue to affect a meaningful portion of users.

The path forward leads to macOS 26.4, which promises the long-delayed Siri improvements and, hopefully, the window resize fix that was teased and then yanked. Until then, update to 26.3 for the security benefits, be aware of the known issues, and consider the third-party workarounds outlined above for the problems that remain.

This article will be updated as new information becomes available about macOS 26.3 post-release issues and the macOS 26.4 beta timeline. Last updated: February 12, 2026.