Apple released the second round of release candidates for macOS Tahoe 26.7 and macOS Sequoia 15.8. The move reflects an intensifying security maintenance cycle that now spans two major macOS versions simultaneously; Apple is shipping point releases to Tahoe (current), and Sequoia (one generation back), in overlapping cycles.
RC2 follows the first release candidates issued exactly one week prior on August 17. Both Tahoe 26.7 and Sequoia 15.8 carry security-focused release notes.
Why Two macOS Versions Are Getting Updates at Once
Apple is maintaining Sequoia and Tahoe because many users have not yet upgraded to the current version, leaving older systems as targets for lingering security gaps. Last week’s release paired macOS 26.6.2 alongside macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9, which fixed a serious Screen Sharing vulnerability affecting all three systems. This extended support window contrasts with Apple’s historical practice of focusing patches primarily on the current version and the immediately preceding release.
By actively patching Sequoia alongside Tahoe, Apple is acknowledging the reality of enterprise deployments and users on older hardware. Many Mac users do not upgrade within months of release, and keeping them secure benefits the entire system by reducing vector points for malware and data theft.
Release Candidate 2 typically means public availability within days rather than weeks, assuming no critical issues emerge during testing. Both Tahoe 26.7 and Sequoia 15.8 should reach general availability shortly after RC validation completes. The parallel testing of multiple RC cycles suggests Apple is validating each version in parallel rather than sequentially, accelerating the path to public release.
WebKit Vulnerabilities and Safari Security
Recent weeks have shown a recurring pattern of WebKit fixes across multiple macOS versions. WebKit vulnerabilities in Safari and third-party browsers put user data at risk, making these patches particularly critical for systems that are no longer receiving major feature updates. The Screen Sharing flaw patched on August 17 shows how a single vulnerability can affect legacy systems months or years after their release; fixing it across Sonoma, Sequoia, and Tahoe prevents attackers from exploiting the age difference between versions as an attack surface.
Apple’s approach prioritizes browser security parity across its installed base rather than pushing users toward the newest OS through security coercion, a pragmatic stance for a company whose user base skews toward professionals and organizations that cannot upgrade quickly.