Tuesday , September 8 2026
macOS

Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS

Apple has put out security updates for macOS, iOS, and iPadOS. These updates fix 28 problems that could let users lose data, crash apps, access kernel memory, and run unwanted code. The updates came out on August 17, 2026. They have macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and iPadOS 18.7.10. The company said these patches fix issues from earlier iOS, iPadOS, and macOS beta versions.

Apple keeps technical details about security flaws secret until it finishes its investigation and releases security updates to everyone. Several flaws affect parts that handle media, web content, and graphics. Apple fixed an overflow issue in ImageIO that might let a specially made image run unwanted code. Another problem in ImageIO could make a vulnerable device crash when it processes a harmful image.

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. These products were made by...
Read More
India: C-DOT Launches 14 Local Quantum-Safe Technologies

14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Microsoft has launched Project Zenith, a new Windows 11 experience for developers. It is made for powerful PCs that can...
Read More
Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Google issues warning of new Chrome zero-day flaw exploited

Google has updated the Chrome browser to fix a serious security issue in the V8 engine and 11 other flaws....
Read More
Google issues warning of new Chrome zero-day flaw exploited

Apple Fixes 28 Security Vulnerabilities

The updates fix several problems in IOGPUFamily, which is an Apple graphics tool. Apple said that bad web content could harm memory.

Remote attackers could use other problems to shut down a system suddenly or let a local app view kernel memory. These issues are serious because the kernel has high permissions and manages important operating system tasks.

An extra kernel-level problem in the older iOS 18.7.10 and iPadOS 18.7.10 versions could let a bad app run harmful code with kernel control through a buffer overflow. Apple fixed this problem by better checking sizes. Apple also fixed an Audio logic issue that could let an app reveal private user information. They solved it by adding better checks. This problem affects both macOS Tahoe 26.6.2 and the new iOS and iPadOS versions.

The mobile updates have a fix for Accessibility for devices on iOS 18.7.10 and iPadOS 18.7.10. Apple said someone with direct access could get sensitive data when using iPhone Mirroring. This feature connects an iPhone to a Mac. The problem was fixed by better state management.

Apple fixed an IPSec authentication problem in iOS 26.6.1 and iPadOS 26.6.1. A bad actor with special access could get around IPSec authentication and capture network data, which is dangerous for users on risky or hacked networks.

iOS 26.6.1 and iPadOS 26.6.1 are available for iPhone 11 and later, supported iPad Pro models, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

The iOS 18.7.10 and iPadOS 18.7.10 updates keep older devices like the iPhone XS, iPhone XS Max, iPhone XR, and iPad 7th generation safe. Users should update quickly. Apple says you cannot go back to an older version of software for iPhone, iPad, Apple TV, Apple Watch, and Vision Pro after updating.

CVE Component Affected release(s) Impact Vulnerability type / remediation
CVE-2026-65339 Audio iOS/iPadOS 26.6.1; macOS Tahoe 26.6.2 An app may leak sensitive user information Logic issue; improved checks
CVE-2026-65347 ImageIO iOS/iPadOS; macOS Processing an image may cause DoS Improved checks
CVE-2026-65346 ImageIO iOS/iPadOS; macOS Processing an image may enable arbitrary code execution Integer overflow; improved input validation
CVE-2026-64788 IOGPUFamily iOS/iPadOS; macOS Crafted web content may cause memory corruption Improved memory handling
CVE-2026-65343 Kernel iOS/iPadOS; macOS Remote attacker may terminate the system Use-after-free; improved memory management
CVE-2026-65349 Kernel iOS/iPadOS; macOS App may terminate the system or read kernel memory Out-of-bounds read; improved input validation
CVE-2026-65330 Kernel iOS/iPadOS; macOS App may terminate the system or corrupt kernel memory Improved memory handling
CVE-2026-65329 Telephony iOS 26.6.1 only; iPhone 11 and later Privileged network attacker may bypass IPSec authentication and intercept traffic Authentication issue; improved state management
CVE-2026-64784 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Out-of-bounds access; improved bounds checking
CVE-2026-43795 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved memory handling
CVE-2026-65338 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved memory handling
CVE-2026-65341 WebKit iOS/iPadOS; macOS Crafted web content may cause memory corruption Improved memory handling
CVE-2026-64782 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Memory-corruption flaw; improved locking
CVE-2026-64781 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved input validation
CVE-2026-65351 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved state management
CVE-2026-65340 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved state management
CVE-2026-65337 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved state management
CVE-2026-65336 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved state management
CVE-2026-65335 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved state management
CVE-2026-65333 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved state management
CVE-2026-65332 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved state management
CVE-2026-65331 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved state management
CVE-2026-64715 WebKit iOS/iPadOS; macOS Crafted web content may cause an unexpected process crash Use-after-free; improved memory management
CVE-2026-64780 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Improved checks
CVE-2026-65334 WebKit iOS/iPadOS; macOS Crafted web content may crash Safari Memory-corruption flaw; improved state management
CVE-2026-43794 WebKit iOS/iPadOS; macOS Crafted web content may cause memory corruption Memory-corruption flaw; improved memory handling
CVE-2026-64787 WebKit iOS/iPadOS; macOS Crafted web content may terminate a process Use-after-free; improved memory management
CVE-2026-64778 WebKit History iOS/iPadOS; macOS Visiting a crafted website may leak sensitive data Improved checks
CVE-2026-64779 WebKit Storage iOS/iPadOS; macOS Crafted web content may crash Safari Memory-corruption flaw; improved locking

Check Also

Chrome

Google issues warning of new Chrome zero-day flaw exploited

Google has updated the Chrome browser to fix a serious security issue in the V8 …