{"id":101870,"date":"2024-09-20T09:07:58","date_gmt":"2024-09-20T16:07:58","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=101870"},"modified":"2024-10-30T12:01:30","modified_gmt":"2024-10-30T19:01:30","slug":"macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/","title":{"rendered":"macOS Sequoia and iOS 18: What Apple patched\u2014and what they didn&#8217;t"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-101866\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-600x300-1.jpg\" alt=\"\" width=\"600\" height=\"300\" \/><\/p>\n<p>Along with any brand-new operating system from Apple comes a variety of new security and privacy features and improvements. Inevitably, these updates also bundle many vulnerability patches that Apple will never backport to earlier OS versions.<\/p>\n<p>Let&#8217;s briefly explore what&#8217;s new in that regard for macOS Sequoia, iOS 18, and the other operating systems Apple released on Monday.<\/p>\n<p>And just as importantly, let&#8217;s also explore what Apple notably <em>didn&#8217;t\u00a0<\/em>patch in this week&#8217;s major new OS updates.<\/p>\n<p>In this article:<\/p>\n<ul>\n<li><a href=\"#features\">New security and privacy features<\/a><\/li>\n<li><a href=\"#oses\">Vulnerabilities patched in the new operating systems<\/a><\/li>\n<li><a href=\"#othersw\">Vulnerabilities patched in other software<\/a><\/li>\n<li><a href=\"#notpatched\">What Apple has (once again) left unpatched<\/a><\/li>\n<li><a href=\"#learnmore\">How can I learn more?<\/a><a name=\"features\"><\/a><\/li>\n<\/ul>\n<h3>New security and privacy features<\/h3>\n<p>We&#8217;ve previously shared our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/top-5-security-and-privacy-features-of-macos-sequoia-ios-18-and-ipados-18\/\" target=\"_blank\" rel=\"noopener\">top 5 list of security and privacy features in macOS Sequoia, iOS 18, and iPadOS 18<\/a>.<\/p>\n<p>One big change is that <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-and-ios-keychain-tutorial-how-apples-icloud-keychain-works\/\">Apple now has a Passwords app<\/a>\u2014an improvement over saved passwords being buried deep within Settings. Another cross-OS improvement that Apple hasn&#8217;t implemented yet is Private Cloud Compute, a key component of Apple Intelligence; it ensures that off-device AI processing maintains users&#8217; privacy.<\/p>\n<p>Most of the other changes are iOS and iPadOS specific. One is locking and hiding apps. Apple has also added the ability to manually select specific contacts to share with an app.<a name=\"oses\"><\/a><\/p>\n<h3>Vulnerabilities patched in the new operating systems<\/h3>\n<p>Apple patched <a href=\"https:\/\/support.apple.com\/en-us\/100100\">a slew of security vulnerabilities<\/a> in its latest operating systems; following is an overview:<\/p>\n<ul>\n<li>macOS Sequoia 15.0 \u2014 49+ CVEs, 35+ additional recognitions<\/li>\n<li>iOS 18.0 and iPadOS 18 \u2014 33+ CVEs, 20+ additional recognitions<\/li>\n<li>watchOS 11.0 \u2014 11+ CVEs, 6+ additional recognitions<\/li>\n<li>visionOS 2.0 \u2014 15+ CVEs, 5+ additional recognitions<\/li>\n<li>tvOS 18.0 \u2014 11+ CVEs, 3+ additional recognitions<\/li>\n<\/ul>\n<p>&#8220;CVEs&#8221; is short for Common Vulnerabilities and Exposures; more specifically, I&#8217;m using the term to refer to the numbers assigned to individual vulnerabilities that Apple patched. Apple sometimes withholds revealing some CVEs until a later date.<\/p>\n<p>&#8220;Additional recognitions&#8221; refers to when Apple only thanks researchers for their assistance, but doesn&#8217;t assign CVE numbers. Because Apple lists operating system components along with a list of researchers, it can be difficult to tell which researchers collaborated or not, and how many issues were reported per component.<\/p>\n<p>Apple did not disclose any &#8220;exploited&#8221; vulnerabilities (i.e. ones previously used in real-world attacks) in this patch cycle.<a name=\"othersw\"><\/a><\/p>\n<h3>Vulnerabilities patched in other software<\/h3>\n<p>Apple also issued some patches for some older operating systems as well as Xcode:<\/p>\n<ul>\n<li>macOS Sonoma 14.7 \u2014 37+ CVEs, 1 additional recognition<\/li>\n<li>macOS Ventura 13.7 \u2014 30+ CVEs, 1 additional recognition<\/li>\n<li>Safari 18 for Sonoma and Ventura \u2014 3+ CVEs, 1+ additional recognitions<\/li>\n<li>iOS 17.7 and iPadOS 17.7 \u2014 16+ CVEs, 0 additional recognitions<\/li>\n<li>Xcode 16 \u2014 3+ CVEs, 2+ additional recognitions<\/li>\n<\/ul>\n<p>Note that there are significant differences between the number of vulnerabilities Apple patched for the current versus previous OS versions. For reasons that Apple has never fully explained, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apples-poor-patching-policies-potentially-make-users-security-and-privacy-precarious\/\">only the current OS versions are fully patched<\/a>; older OSes get a subset of applicable patches.<\/p>\n<p>Apple did not release a watchOS 10 security update. This leaves the Apple Watch Series 4, Series 5, and SE (1st gen)\u2014all of which can&#8217;t run watchOS 11\u2014without any new security updates.<a name=\"notpatched\"><\/a><\/p>\n<h3>What Apple has (once again) left unpatched<\/h3>\n<p>Apple continues to leave open-source software components in macOS Sequoia <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/\">critically outdated and highly vulnerable<\/a>. For example, Sequoia still includes LibreSSL 3.3.6, which is more than 2.5 years old and contains at least <a href=\"https:\/\/nvd.nist.gov\/vuln\/search\/results?form_type=Advanced&amp;results_type=overview&amp;isCpeNameSearch=true&amp;seach_type=all&amp;query=cpe:2.3:a:openbsd:libressl:3.3.6:*:*:*:*:*:*:*\" target=\"_blank\" rel=\"noopener\">four known vulnerabilities<\/a>, including two rated &#8220;9.8 CRITICAL&#8221; on the CVSS scale; the latest stable release is 3.9.2, released on May 12, 2024.<\/p>\n<p>Additionally, Apple has once again neglected to patch a Safari bug that the company has known about for more than 5.5 years. The bug makes it easy to spread misinformation via <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-neglects-to-fix-fake-headlines-bug-usable-for-election-interference\/\">fake news headlines<\/a> that appears to come from credible sources.<\/p>\n<p>We&#8217;ve reached out to Apple about both of these issues. Apple has not responded to our requests for comment.<\/p>\n<p>Meanwhile, macOS Sequoia 15.0 has <a href=\"https:\/\/appleinsider.com\/articles\/24\/09\/19\/macos-sequoia-causing-issues-with-third-party-security-tools-and-web-browsers\" target=\"_blank\" rel=\"noopener\">introduced a new network-related bug<\/a> that has impacted many users. Due to this Apple bug, some apps may have difficulty accessing the Internet; this seems to be especially common for <a href=\"https:\/\/www.intego.com\/mac-security-blog\/why-you-should-connect-to-a-vpn-on-mac-and-ios-and-how-to\/\">VPN<\/a> users. Apple is aware of the bug and will likely release an update soon to address it.<a name=\"learnmore\"><\/a><\/p>\n<h3>How can I learn more?<\/h3>\n<p><a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><img class=\"alignleft\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/04\/intego-podcast-artwork-400.jpg\" alt=\"\" width=\"80\" \/><\/a>Each week on the <a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Intego Mac Podcast<\/strong><\/a>, Intego&#8217;s Mac security experts discuss the latest Apple news, security and privacy stories, and offer practical advice on getting the most out of your Apple devices. Be sure to <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" rel=\"noopener\"><strong>follow the podcast<\/strong><\/a> to make sure you don\u2019t miss any episodes.<\/p>\n<p>You can also subscribe to our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-security-newsletter\/\"><strong>e-mail newsletter<\/strong><\/a> and keep an eye here on <a href=\"https:\/\/www.intego.com\/mac-security-blog\"><strong>The Mac Security Blog<\/strong><\/a> for the latest Apple security and privacy news. And don&#8217;t forget to follow Intego on your favorite social media channels: <a href=\"https:\/\/x.com\/IntegoSecurity\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on \ud835\udd4f\/Twitter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/X-Twitter-logo-icon-225.gif\" alt=\"Follow Intego on X\/Twitter\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.facebook.com\/Intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Facebook\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Facebook-logo-icon-225.gif\" alt=\"Follow Intego on Facebook\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.youtube.com\/user\/IntegoVideo?sub_confirmation=1\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on YouTube\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/YouTube-logo-icon-225.png\" alt=\"Follow Intego on YouTube\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.pinterest.com\/intego\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on Pinterest\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Pinterest-logo-icon-225.png\" alt=\"Follow Intego on Pinterest\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on LinkedIn\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/LinkedIn-logo-icon-225.gif\" alt=\"Follow Intego on LinkedIn\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.instagram.com\/intego_security\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Instagram\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Instagram-logo-icon-225.gif\" alt=\"Follow Intego on Instagram\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow the Intego Mac Podcast on Apple Podcasts\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png\" alt=\"Follow the Intego Mac Podcast on Apple Podcasts\" width=\"16\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple\u2019s new operating systems, including macOS Sequoia and iOS 18, include a number of security improvements. But Apple continues to neglect to\u00a0patch some major vulnerabilities as well.<\/p>\n","protected":false},"author":14,"featured_media":101868,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[13],"tags":[4687,4684,4741,4742,4740,4686,4643,115,201,143,170],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Apple\u2019s new operating systems, including macOS Sequoia and iOS 18, include a number of security improvements. But Apple continues to neglect to\u00a0patch some major vulnerabilities as well.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"macOS Sequoia and iOS 18: What Apple patched\u2014and what they didn&#039;t - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Apple\u2019s new operating systems, including macOS Sequoia and iOS 18, include a number of security improvements. But Apple continues to neglect to\u00a0patch some major vulnerabilities as well.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/JoshLong\" \/>\n<meta property=\"article:published_time\" content=\"2024-09-20T16:07:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-10-30T19:01:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-400x260-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@theJoshMeister\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joshua Long\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-400x260-1.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-400x260-1.jpg\",\"width\":400,\"height\":260,\"caption\":\"Apple software security update macOS Sequoia red\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/\",\"name\":\"macOS Sequoia and iOS 18: What Apple patched\\u2014and what they didn't - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#primaryimage\"},\"datePublished\":\"2024-09-20T16:07:58+00:00\",\"dateModified\":\"2024-10-30T19:01:30+00:00\",\"description\":\"Apple\\u2019s new operating systems, including macOS Sequoia and iOS 18, include a number of security improvements. But Apple continues to neglect to\\u00a0patch some major vulnerabilities as well.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"macOS Sequoia and iOS 18: What Apple patched\\u2014and what they didn&#8217;t\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\"},\"headline\":\"macOS Sequoia and iOS 18: What Apple patched\\u2014and what they didn&#8217;t\",\"datePublished\":\"2024-09-20T16:07:58+00:00\",\"dateModified\":\"2024-10-30T19:01:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#webpage\"},\"wordCount\":750,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-400x260-1.jpg\",\"keywords\":[\"Apple Vision Pro\",\"iOS 17\",\"iOS 18\",\"iPadOS 18\",\"macOS Sequoia\",\"macOS Sonoma\",\"macOS Ventura\",\"Safari\",\"Security Updates\",\"Vulnerabilities\",\"Xcode\"],\"articleSection\":[\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\",\"name\":\"Joshua Long\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"caption\":\"Joshua Long\"},\"description\":\"Joshua Long (@theJoshMeister), formerly Intego\\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \\u2014\",\"sameAs\":[\"https:\/\/security.thejoshmeister.com\",\"https:\/\/www.facebook.com\/JoshLong\",\"https:\/\/www.instagram.com\/thejoshmeister\/\",\"https:\/\/www.linkedin.com\/in\/thejoshmeister\",\"https:\/\/www.pinterest.com\/thejoshmeister\/\",\"https:\/\/twitter.com\/theJoshMeister\",\"https:\/\/www.youtube.com\/@theJoshMeister\"],\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Apple\u2019s new operating systems, including macOS Sequoia and iOS 18, include a number of security improvements. But Apple continues to neglect to\u00a0patch some major vulnerabilities as well.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/","og_locale":"en_US","og_type":"article","og_title":"macOS Sequoia and iOS 18: What Apple patched\u2014and what they didn't - The Mac Security Blog","og_description":"Apple\u2019s new operating systems, including macOS Sequoia and iOS 18, include a number of security improvements. But Apple continues to neglect to\u00a0patch some major vulnerabilities as well.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/","og_site_name":"The Mac Security Blog","article_author":"https:\/\/www.facebook.com\/JoshLong","article_published_time":"2024-09-20T16:07:58+00:00","article_modified_time":"2024-10-30T19:01:30+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-400x260-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_creator":"@theJoshMeister","twitter_misc":{"Written by":"Joshua Long","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-400x260-1.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-400x260-1.jpg","width":400,"height":260,"caption":"Apple software security update macOS Sequoia red"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/","name":"macOS Sequoia and iOS 18: What Apple patched\u2014and what they didn't - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#primaryimage"},"datePublished":"2024-09-20T16:07:58+00:00","dateModified":"2024-10-30T19:01:30+00:00","description":"Apple\u2019s new operating systems, including macOS Sequoia and iOS 18, include a number of security improvements. But Apple continues to neglect to\u00a0patch some major vulnerabilities as well.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"macOS Sequoia and iOS 18: What Apple patched\u2014and what they didn&#8217;t"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1"},"headline":"macOS Sequoia and iOS 18: What Apple patched\u2014and what they didn&#8217;t","datePublished":"2024-09-20T16:07:58+00:00","dateModified":"2024-10-30T19:01:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#webpage"},"wordCount":750,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-400x260-1.jpg","keywords":["Apple Vision Pro","iOS 17","iOS 18","iPadOS 18","macOS Sequoia","macOS Sonoma","macOS Ventura","Safari","Security Updates","Vulnerabilities","Xcode"],"articleSection":["Security &amp; Privacy"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/macos-sequoia-and-ios-18-what-apple-patched-and-what-they-didnt\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1","name":"Joshua Long","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","caption":"Joshua Long"},"description":"Joshua Long (@theJoshMeister), formerly Intego\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \u2014","sameAs":["https:\/\/security.thejoshmeister.com","https:\/\/www.facebook.com\/JoshLong","https:\/\/www.instagram.com\/thejoshmeister\/","https:\/\/www.linkedin.com\/in\/thejoshmeister","https:\/\/www.pinterest.com\/thejoshmeister\/","https:\/\/twitter.com\/theJoshMeister","https:\/\/www.youtube.com\/@theJoshMeister"],"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/09\/Apple-software-security-update-macOS-Sequoia-red-400x260-1.jpg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-qv4","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/101870"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=101870"}],"version-history":[{"count":6,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/101870\/revisions"}],"predecessor-version":[{"id":102223,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/101870\/revisions\/102223"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/101868"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=101870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=101870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=101870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}