Apple Patches iOS and macOS
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
None of the vulnerabilities has been exploited so far. There are a few WebKit vulnerabilities, but no standalone Safari patch for older operating systems. 87 of the vulnerabilities affect only iOS 18, making this more of an iOS 18 release than one for the newer operating systems. Only six vulnerabilities affect all three OSs released today. All 6 vulnerabilities affect WebKit.
Apple's vulnerability summary notes that the vulnerabilities patched in today's VisionOS release will be enumerated at a later date.
| iOS 26.6.1 and iPadOS 26.6.1 | iOS 18.7.10 and iPadOS 18.7.10 | macOS Tahoe 26.6.2 |
|---|---|---|
| CVE-2026-28958: An app may be able to access sensitive user data. Affects WebKit |
||
| x | ||
| CVE-2026-28973: A malicious app may be able to break out of its sandbox. Affects libc |
||
| x | ||
| CVE-2026-28984: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | ||
| CVE-2026-28990: Processing a maliciously crafted image may corrupt process memory. Affects ImageIO |
||
| x | ||
| CVE-2026-28996: An app may be able to access sensitive user data. Affects Storage |
||
| x | ||
| CVE-2026-39868: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
||
| x | ||
| CVE-2026-39877: An app may be able to disclose kernel memory. Affects IOSkywalkFamily |
||
| x | ||
| CVE-2026-43661: Processing a maliciously crafted image may corrupt process memory. Affects ImageIO |
||
| x | ||
| CVE-2026-43663: Processing maliciously crafted web content may lead to an unexpected process crash. Affects WebKit |
||
| x | ||
| CVE-2026-43667: An attacker in a privileged network position may be able to cause a denial-of-service. Affects AirDrop |
||
| x | ||
| CVE-2026-43673: Processing a maliciously crafted audio file may corrupt process memory. Affects CoreAudio |
||
| x | ||
| CVE-2026-43676: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | ||
| CVE-2026-43700: Processing maliciously crafted web content may disclose sensitive user information. Affects WebKit |
||
| x | ||
| CVE-2026-43701: A malicious website may be able to process restricted web content outside the sandbox. Affects WebKit |
||
| x | ||
| CVE-2026-43705: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit |
||
| x | ||
| CVE-2026-43708: A malicious website may exfiltrate data cross-origin. Affects WebKit |
||
| x | ||
| CVE-2026-43711: Processing a maliciously crafted video file may lead to unexpected app termination. Affects CoreMedia |
||
| x | ||
| CVE-2026-43714: A malicious app may be able to access protected user data. Affects Foundation |
||
| x | ||
| CVE-2026-43717: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebRTC |
||
| x | ||
| CVE-2026-43720: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit Canvas |
||
| x | ||
| CVE-2026-43722: An app may be able to leak sensitive kernel state. Affects Kernel |
||
| x | ||
| CVE-2026-43723: An app may be able to gain root privileges. Affects MediaRemote |
||
| x | ||
| CVE-2026-43724: An app may be able to cause unexpected system termination or write kernel memory. Affects Kernel |
||
| x | ||
| CVE-2026-43725: A malicious website may be able to process restricted web content outside the sandbox. Affects WebKit |
||
| x | ||
| CVE-2026-43727: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | ||
| CVE-2026-43729: Processing a maliciously crafted image may corrupt process memory. Affects Model I/O |
||
| x | ||
| CVE-2026-43731: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit |
||
| x | ||
| CVE-2026-43735: A malicious website may exfiltrate data cross-origin. Affects WebKit |
||
| x | ||
| CVE-2026-43738: Processing a maliciously crafted asset catalog may result in disclosure of process memory. Affects CoreUI |
||
| x | ||
| CVE-2026-43742: Processing maliciously crafted web content may lead to an unexpected process crash. Affects WebKit |
||
| x | ||
| CVE-2026-43744: Processing an audio stream in a maliciously crafted media file may terminate the process. Affects CoreAudio |
||
| x | ||
| CVE-2026-43745: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | ||
| CVE-2026-43754: An app may be able to leak sensitive kernel state. Affects Kernel |
||
| x | ||
| CVE-2026-43757: An app may be able to cause unexpected system termination. Affects Kernel |
||
| x | ||
| CVE-2026-43769: An app may be able to cause unexpected system termination. Affects Kernel |
||
| x | ||
| CVE-2026-43776: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. Affects AppleDouble |
||
| x | ||
| CVE-2026-43778: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
||
| x | ||
| CVE-2026-43794: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit |
||
| x | x | x |
| CVE-2026-43796: An app may be able to read a persistent device identifier. Affects Game Center |
||
| x | ||
| CVE-2026-43797: An app may be able to access information about a user's contacts. Affects Contacts |
||
| x | ||
| CVE-2026-43800: An app may be able to access sensitive user data. Affects Siri |
||
| x | ||
| CVE-2026-43801: An app may be able to access sensitive user data. Affects App Store |
||
| x | ||
| CVE-2026-43802: An app may be able to cause unexpected system termination. Affects CoreVideo |
||
| x | ||
| CVE-2026-43803: A remote attacker may be able to cause unexpected system termination. Affects CoreAudio |
||
| x | ||
| CVE-2026-43807: A malicious accessory may be able to cause unexpected app termination. Affects MobileAccessoryUpdater |
||
| x | ||
| CVE-2026-43810: A remote user may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
||
| x | ||
| CVE-2026-43811: An app may be able to modify protected parts of the file system. Affects Books |
||
| x | ||
| CVE-2026-43812: An app may be able to cause unexpected system termination. Affects Pro Res |
||
| x | ||
| CVE-2026-43818: Processing a maliciously crafted image may lead to arbitrary code execution. Affects ImageIO |
||
| x | ||
| CVE-2026-43821: An app may be able to read files outside of its sandbox. Affects WebKit Process Model |
||
| x | ||
| CVE-2026-64692: An app may be able to cause a denial-of-service. Affects Heimdal |
||
| x | ||
| CVE-2026-64693: Processing a maliciously crafted image may lead to a denial-of-service. Affects ImageIO |
||
| x | ||
| CVE-2026-64695: A remote user may be able to cause unexpected system termination or corrupt kernel memory. Affects APFS |
||
| x | ||
| CVE-2026-64700: An app may be able to cause unexpected system termination. Affects Kernel |
||
| x | ||
| CVE-2026-64707: An app may be able to delete files for which it does not have permission. Affects BackgroundAssets |
||
| x | ||
| CVE-2026-64709: An app may be able to disclose kernel memory. Affects Kernel |
||
| x | ||
| CVE-2026-64715: Processing maliciously crafted web content may lead to an unexpected process crash. Affects WebKit |
||
| x | x | |
| CVE-2026-64719: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebRTC |
||
| x | ||
| CVE-2026-64721: An app may be able to access sensitive user data. Affects Kernel |
||
| x | ||
| CVE-2026-64722: Processing a 3D model may result in disclosure of process memory. Affects Model I/O |
||
| x | ||
| CVE-2026-64723: An app may be able to access sensitive user data. Affects Kernel |
||
| x | ||
| CVE-2026-64724: An attacker on the local network may be able to cause a denial-of-service. Affects mDNSResponder |
||
| x | ||
| CVE-2026-64725: An app may be able to cause a denial-of-service. Affects Audio |
||
| x | ||
| CVE-2026-64726: An attacker in physical proximity may be able to corrupt process memory. Affects Wi-Fi |
||
| x | ||
| CVE-2026-64732: An attacker with physical access may be able to access sensitive user data during iPhone Mirroring. Affects Accessibility |
||
| x | ||
| CVE-2026-64734: Processing a maliciously crafted contact may leak sensitive data. Affects Contacts |
||
| x | ||
| CVE-2026-64735: A remote attacker may be able to bypass network filters. Affects Kernel |
||
| x | ||
| CVE-2026-64738: A malicious app may be able to break out of its sandbox. Affects Maps |
||
| x | ||
| CVE-2026-64739: An attacker may be able to cause unexpected app termination. Affects Libnotify |
||
| x | ||
| CVE-2026-64740: A malicious app may be able to break out of its sandbox. Affects Game Center |
||
| x | ||
| CVE-2026-64742: An app may be able to access sensitive user data. Affects FrontBoard |
||
| x | ||
| CVE-2026-64743: An app may be able to access sensitive user data. Affects Managed Configuration |
||
| x | ||
| CVE-2026-64744: An app may be able to disclose kernel memory. Affects Kernel |
||
| x | ||
| CVE-2026-64746: An app may be able to add contacts without user authorization. Affects Contacts |
||
| x | ||
| CVE-2026-64747: An app may be able to execute arbitrary code with kernel privileges. Affects AVEVideoEncoder |
||
| x | ||
| CVE-2026-64749: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
||
| x | ||
| CVE-2026-64755: An app may be able to access sensitive user data. Affects WorkoutKit |
||
| x | ||
| CVE-2026-64757: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | ||
| CVE-2026-64760: An app may be able to leak sensitive kernel state. Affects IOSurfaceAccelerator |
||
| x | ||
| CVE-2026-64762: An app may be able to cause unexpected system termination. Affects AVEVideoEncoder |
||
| x | ||
| CVE-2026-64763: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. Affects SceneKit |
||
| x | ||
| CVE-2026-64764: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. Affects SceneKit |
||
| x | ||
| CVE-2026-64765: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. Affects SceneKit |
||
| x | ||
| CVE-2026-64768: A remote attacker may cause an unexpected app termination. Affects Model I/O |
||
| x | ||
| CVE-2026-64769: A remote attacker may be able to cause unexpected application termination or heap corruption. Affects Model I/O |
||
| x | ||
| CVE-2026-64771: A remote attacker may be able to cause unexpected application termination or heap corruption. Affects Model I/O |
||
| x | ||
| CVE-2026-64772: A remote attacker may be able to cause unexpected application termination or heap corruption. Affects Model I/O |
||
| x | ||
| CVE-2026-64774: A remote attacker may be able to cause unexpected application termination or heap corruption. Affects Model I/O |
||
| x | ||
| CVE-2026-64778: Visiting a maliciously crafted website may leak sensitive data. Affects WebKit History |
||
| x | x | x |
| CVE-2026-64779: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit Storage |
||
| x | x | x |
| CVE-2026-64780: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | x | x |
| CVE-2026-64781: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | x | x |
| CVE-2026-64782: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | x | x |
| CVE-2026-64784: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | x | |
| CVE-2026-64787: Processing maliciously crafted web content may lead to an unexpected process termination. Affects WebKit |
||
| x | x | |
| CVE-2026-64788: Processing maliciously crafted web content may lead to memory corruption. Affects IOGPUFamily |
||
| x | x | |
| CVE-2026-65329: An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic. Affects Telephony |
||
| x | ||
| CVE-2026-65330: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
||
| x | x | |
| CVE-2026-65331: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | x | |
| CVE-2026-65334: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | x | |
| CVE-2026-65338: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | x | |
| CVE-2026-65339: An app may be able to leak sensitive user information. Affects Audio |
||
| x | x | |
| CVE-2026-65340: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
||
| x | ||
| CVE-2026-65341: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit |
||
| x | x | x |
| CVE-2026-65343: A remote attacker may be able to cause unexpected system termination. Affects Kernel |
||
| x | x | |
| CVE-2026-65346: Processing an image may lead to arbitrary code execution. Affects ImageIO |
||
| x | x | |
| CVE-2026-65347: Processing an image may lead to a denial-of-service. Affects ImageIO |
||
| x | x | |
| CVE-2026-65349: An app may be able to cause unexpected system termination or read kernel memory. Affects Kernel |
||
| x | x | |
--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

Comments