Apple has put out security updates for macOS, iOS, and iPadOS. These updates fix 28 problems that could let users lose data, crash apps, access kernel memory, and run unwanted code. The updates came out on August 17, 2026. They have macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and iPadOS 18.7.10. The company said these patches fix issues from earlier iOS, iPadOS, and macOS beta versions.
Apple keeps technical details about security flaws secret until it finishes its investigation and releases security updates to everyone. Several flaws affect parts that handle media, web content, and graphics. Apple fixed an overflow issue in ImageIO that might let a specially made image run unwanted code. Another problem in ImageIO could make a vulnerable device crash when it processes a harmful image.
Apple Fixes 28 Security Vulnerabilities
The updates fix several problems in IOGPUFamily, which is an Apple graphics tool. Apple said that bad web content could harm memory.
Remote attackers could use other problems to shut down a system suddenly or let a local app view kernel memory. These issues are serious because the kernel has high permissions and manages important operating system tasks.
An extra kernel-level problem in the older iOS 18.7.10 and iPadOS 18.7.10 versions could let a bad app run harmful code with kernel control through a buffer overflow. Apple fixed this problem by better checking sizes. Apple also fixed an Audio logic issue that could let an app reveal private user information. They solved it by adding better checks. This problem affects both macOS Tahoe 26.6.2 and the new iOS and iPadOS versions.
The mobile updates have a fix for Accessibility for devices on iOS 18.7.10 and iPadOS 18.7.10. Apple said someone with direct access could get sensitive data when using iPhone Mirroring. This feature connects an iPhone to a Mac. The problem was fixed by better state management.
Apple fixed an IPSec authentication problem in iOS 26.6.1 and iPadOS 26.6.1. A bad actor with special access could get around IPSec authentication and capture network data, which is dangerous for users on risky or hacked networks.
iOS 26.6.1 and iPadOS 26.6.1 are available for iPhone 11 and later, supported iPad Pro models, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
The iOS 18.7.10 and iPadOS 18.7.10 updates keep older devices like the iPhone XS, iPhone XS Max, iPhone XR, and iPad 7th generation safe. Users should update quickly. Apple says you cannot go back to an older version of software for iPhone, iPad, Apple TV, Apple Watch, and Vision Pro after updating.
| CVE | Component | Affected release(s) | Impact | Vulnerability type / remediation |
|---|---|---|---|---|
| CVE-2026-65339 | Audio | iOS/iPadOS 26.6.1; macOS Tahoe 26.6.2 | An app may leak sensitive user information | Logic issue; improved checks |
| CVE-2026-65347 | ImageIO | iOS/iPadOS; macOS | Processing an image may cause DoS | Improved checks |
| CVE-2026-65346 | ImageIO | iOS/iPadOS; macOS | Processing an image may enable arbitrary code execution | Integer overflow; improved input validation |
| CVE-2026-64788 | IOGPUFamily | iOS/iPadOS; macOS | Crafted web content may cause memory corruption | Improved memory handling |
| CVE-2026-65343 | Kernel | iOS/iPadOS; macOS | Remote attacker may terminate the system | Use-after-free; improved memory management |
| CVE-2026-65349 | Kernel | iOS/iPadOS; macOS | App may terminate the system or read kernel memory | Out-of-bounds read; improved input validation |
| CVE-2026-65330 | Kernel | iOS/iPadOS; macOS | App may terminate the system or corrupt kernel memory | Improved memory handling |
| CVE-2026-65329 | Telephony | iOS 26.6.1 only; iPhone 11 and later | Privileged network attacker may bypass IPSec authentication and intercept traffic | Authentication issue; improved state management |
| CVE-2026-64784 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Out-of-bounds access; improved bounds checking |
| CVE-2026-43795 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved memory handling |
| CVE-2026-65338 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved memory handling |
| CVE-2026-65341 | WebKit | iOS/iPadOS; macOS | Crafted web content may cause memory corruption | Improved memory handling |
| CVE-2026-64782 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Memory-corruption flaw; improved locking |
| CVE-2026-64781 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved input validation |
| CVE-2026-65351 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65340 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65337 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65336 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65335 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65333 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65332 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65331 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-64715 | WebKit | iOS/iPadOS; macOS | Crafted web content may cause an unexpected process crash | Use-after-free; improved memory management |
| CVE-2026-64780 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved checks |
| CVE-2026-65334 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Memory-corruption flaw; improved state management |
| CVE-2026-43794 | WebKit | iOS/iPadOS; macOS | Crafted web content may cause memory corruption | Memory-corruption flaw; improved memory handling |
| CVE-2026-64787 | WebKit | iOS/iPadOS; macOS | Crafted web content may terminate a process | Use-after-free; improved memory management |
| CVE-2026-64778 | WebKit History | iOS/iPadOS; macOS | Visiting a crafted website may leak sensitive data | Improved checks |
| CVE-2026-64779 | WebKit Storage | iOS/iPadOS; macOS | Crafted web content may crash Safari | Memory-corruption flaw; improved locking |
InfoSecBulletin Cybersecurity for mankind
