Skip to content

MacPublished 4 min read

The macOS Tahoe 26.7 release candidate leaks over 10 unreleased Apple products (August 19, 2026)

Illustration for the article “The macOS Tahoe 26.7 release candidate leaks over 10 unreleased Apple products (August 19, 2026)”
Listen to this article · 6:39 · AI-generated narration
0:00 / 6:39
Chapters

TL;DR

The macOS Tahoe 26.7 release candidate, a build Apple had already seeded publicly, contains readable references to more than ten unreleased Apple products, according to MacRumors on August 19, 2026. This is an information disclosure defect rather than a crash: there is nothing for a Mac owner to mitigate, and the cost lands on Apple's product secrecy. Apple has not commented, and there is no indication it pulled the build.

  • The leak is in the macOS Tahoe 26.7 release candidate, in code and feature-flag data rather than in any Mac model.
  • Named in the code: AirPods with infrared cameras, a smart home hub, OLED MacBook and iPad mini, a foldable iPhone.
  • Some codenames had appeared in earlier updates, but now carry new feature flags.
  • August 19, 2026 produced no conventional macOS crash or data-loss story in the outlets I checked.
  • The live Mac risk that day was still the Screen Sharing bypass CVE-2026-65400, patched since August 6, 2026.

What is readable in a shipped build

MacRumors published the consolidated write-up at 8:02 am PDT on August 19, 2026, crediting contributor Aaron Perris. Its summary is that "macOS 26.7's code contains references to AirPods with infrared cameras for Visual Intelligence, the long-rumored foldable iPhone, an all-new Apple smart home hub, the first-ever MacBook and iPad mini models with OLED displays, an updated Siri Remote for a next-generation Apple TV, and more". More than ten unreleased products are referenced.

The earlier MacRumors piece from 4:50 pm PDT on August 17, 2026 identifies the source as the macOS Tahoe 26.7 release candidate and lists the codenames. It also makes the point that decides whether this is noise or a defect: "some of these codenames have shown up in prior software updates but have new feature flags". Strings that sit in a build for years are one thing. New feature flags attached to them are a current change.

The codenames in the build

From the August 17, 2026 list: smart home hub codenames J490 and J491, in base and wall-mounted versions; HomePod mini B525; AirPods with integrated cameras under B790; and a J229Architecture reference that suggests a security-focused device, possibly a camera. The same build also references an M6 MacBook Pro, new iMac variants, iPhone Air 2, iPhone 18, iPhone 18 Pro, iPhone 18 Pro Max and a foldable iPhone Ultra.

CodenameWhat it points to
J490 and J491Apple smart home hub, base and wall-mounted versions
B525Updated HomePod mini
B790AirPods with integrated cameras
J229ArchitectureA security-focused device, possibly a camera

Why I am calling this a defect, and what it is not

I will be straight about the pick. This is a quality-assurance and disclosure failure in a public build, not a crash, not data loss, and not a security hole in your Mac. Nothing on your machine behaves differently because those strings are in the release candidate, and there is no setting to change and no patch to wait for. The party that pays for it is Apple, in product secrecy.

It is also not fixable after the fact. Once a build is public, the contents are out, and MacRumors reports no Apple response and no sign that the software was pulled. The only real remedy is procedural, on Apple's side of the fence, before the next release candidate ships.

And August 19, 2026 was a quiet day for genuine macOS faults. This was the dominant macOS build story, and I could not identify a conventional bug report dated that day in the outlets I checked, so this is the honest pick rather than the strongest one.

What Macs were actually at risk that day

The real exposure on August 19, 2026 was still CVE-2026-65400, the Screen Sharing authentication bypass that Apple Support fixed in macOS Tahoe 26.6.1 on August 6, 2026. I covered the exploitation in the August 14 post and the catalogue listing that followed in the August 18 post.

An institutional security alert published the same day by the CUHK Information Technology Services Centre adds something practical the news coverage did not: a host-level indicator of compromise, the launch daemon path /Library/LaunchDaemons/com.xmr.miner.plist. If a Mac of yours had port 5900 open to the internet, that is a concrete file path to go and look for.

What to do today

1. Nothing about the leak needs action on your Mac. If you are running the macOS Tahoe 26.7 release candidate, the thing to remember is what a release candidate is: prerelease software that belongs on a spare machine, not on the Mac you work on.

2. Spend the time on the patch instead. In System Settings, General, Software Update, make sure the Mac is on macOS Tahoe 26.6.2, which Apple Support dates to August 17, 2026, or on macOS Sequoia 15.7.9 or macOS Sonoma 14.8.9.

3. In System Settings, General, Sharing, switch Screen Sharing and Remote Management off unless you actively use them, and stop forwarding TCP port 5900 from the internet.

4. If any Mac was exposed on port 5900, check /Library/LaunchDaemons for com.xmr.miner.plist and for anything else you did not install, and check whether a process is holding the processor at full load.

5. If you found something, stop treating it as a patching problem and get the machine examined.

All articles