Cyber Security News

Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS

Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application crashes, kernel memory access, and arbitrary code execution.

The updates were released on August 17, 2026, and include macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and iPadOS 18.7.10. The company said the patches include fixes that were previously delivered through iOS, iPadOS, and macOS beta releases.

Apple follows a policy of withholding technical details about security flaws until it completes an investigation and security updates are broadly available.

Several flaws affect components that process media, web content, and graphics. Apple fixed an integer overflow in ImageIO that could allow a specially crafted image to trigger arbitrary code execution. A separate ImageIO issue could cause a denial-of-service condition when a vulnerable device processes a malicious image.

Apple Fixes 28 Security Vulnerabilities

The updates also address multiple issues in IOGPUFamily, an Apple graphics framework. Apple warned that malicious web content could cause memory corruption.

At the same time, other flaws could enable remote attackers to terminate a system unexpectedly or allow a local application to read kernel memory. Such bugs are significant because the kernel runs with high privileges and controls core operating-system functions.

An additional kernel-level issue in the older iOS 18.7.10 and iPadOS 18.7.10 releases could allow a malicious application to execute arbitrary code with kernel privileges via a buffer overflow. Apple resolved the flaw through improved size validation.

Apple patched an Audio logic issue that could allow an application to leak sensitive user information. The company addressed the problem by adding improved checks. This vulnerability affects both macOS Tahoe 26.6.2 and the newer iOS and iPadOS releases.

The mobile updates also include an Accessibility fix for devices running iOS 18.7.10 and iPadOS 18.7.10. Apple said an attacker with physical access could potentially access sensitive data during iPhone Mirroring. This feature links an iPhone with a Mac. The issue was fixed through improved state management.

CVEComponentAffected release(s)ImpactVulnerability type / remediation
CVE-2026-65339AudioiOS/iPadOS 26.6.1; macOS Tahoe 26.6.2An app may leak sensitive user informationLogic issue; improved checks
CVE-2026-65347ImageIOiOS/iPadOS; macOSProcessing an image may cause DoSImproved checks
CVE-2026-65346ImageIOiOS/iPadOS; macOSProcessing an image may enable arbitrary code executionInteger overflow; improved input validation
CVE-2026-64788IOGPUFamilyiOS/iPadOS; macOSCrafted web content may cause memory corruptionImproved memory handling
CVE-2026-65343KerneliOS/iPadOS; macOSRemote attacker may terminate the systemUse-after-free; improved memory management
CVE-2026-65349KerneliOS/iPadOS; macOSApp may terminate the system or read kernel memoryOut-of-bounds read; improved input validation
CVE-2026-65330KerneliOS/iPadOS; macOSApp may terminate the system or corrupt kernel memoryImproved memory handling
CVE-2026-65329TelephonyiOS 26.6.1 only; iPhone 11 and laterPrivileged network attacker may bypass IPSec authentication and intercept trafficAuthentication issue; improved state management
CVE-2026-64784WebKitiOS/iPadOS; macOSCrafted web content may crash SafariOut-of-bounds access; improved bounds checking
CVE-2026-43795WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved memory handling
CVE-2026-65338WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved memory handling
CVE-2026-65341WebKitiOS/iPadOS; macOSCrafted web content may cause memory corruptionImproved memory handling
CVE-2026-64782WebKitiOS/iPadOS; macOSCrafted web content may crash SafariMemory-corruption flaw; improved locking
CVE-2026-64781WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved input validation
CVE-2026-65351WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65340WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65337WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65336WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65335WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65333WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65332WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65331WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-64715WebKitiOS/iPadOS; macOSCrafted web content may cause an unexpected process crashUse-after-free; improved memory management
CVE-2026-64780WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved checks
CVE-2026-65334WebKitiOS/iPadOS; macOSCrafted web content may crash SafariMemory-corruption flaw; improved state management
CVE-2026-43794WebKitiOS/iPadOS; macOSCrafted web content may cause memory corruptionMemory-corruption flaw; improved memory handling
CVE-2026-64787WebKitiOS/iPadOS; macOSCrafted web content may terminate a processUse-after-free; improved memory management
CVE-2026-64778WebKit HistoryiOS/iPadOS; macOSVisiting a crafted website may leak sensitive dataImproved checks
CVE-2026-64779WebKit StorageiOS/iPadOS; macOSCrafted web content may crash SafariMemory-corruption flaw; improved locking

Apple also corrected an IPSec authentication issue in iOS 26.6.1 and iPadOS 26.6.1. A threat actor in a privileged network position could bypass IPSec authentication and intercept network traffic, posing a risk to users on hostile or compromised networks.

iOS 26.6.1 and iPadOS 26.6.1 are available for iPhone 11 and later, supported iPad Pro models, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

The iOS 18.7.10 and iPadOS 18.7.10 updates protect older iPhone XS, iPhone XS Max, iPhone XR, and iPad 7th-generation devices. Users should install the updates promptly. Apple notes that iPhone, iPad, Apple TV, Apple Watch, and Vision Pro software cannot be downgraded after an update is installed.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago