Apple has rolled out new security updates for macOS, iOS, and iPadOS to address numerous vulnerabilities. The majority of these flaws are found within WebKit, the web browser engine that powers Safari and other applications.
Users are advised to install these updates promptly to protect against potential security risks, although Apple has not indicated that any of these vulnerabilities are currently being exploited in the wild.
macOS Tahoe 26.6.2 includes fixes for 28 security defects. Of these, 21 are in WebKit and could lead to Safari/process crashes, memory corruption, and sensitive data disclosure. The update also resolves seven issues in components like Audio, ImageIO, IOGPUFamily, and Kernel, which could result in sensitive user information disclosure, denial-of-service, arbitrary code execution, and kernel memory corruption.
iOS 26.6.1 and iPadOS 26.6.1 address all 28 vulnerabilities found in macOS Tahoe 26.6.2. Additionally, these updates fix an authentication issue in Telephony that could allow attackers to bypass IPSec authentication and intercept network traffic.
Apple also released updates for iOS 18.7.10 and iPadOS 18.7.10, which resolve over 120 bugs. More than 40 of these bugs are located in WebKit. These WebKit flaws could lead to crashes, memory corruption, data disclosure, sandbox escape, and cross-origin data exfiltration.
The updates for these older versions also address 18 vulnerabilities in the Kernel. These Kernel flaws could be exploited to corrupt kernel memory, crash the system, disclose kernel memory, bypass network filters, write kernel memory, leak sensitive kernel state, and access sensitive user data.
Beyond WebKit and Kernel, security defects were also addressed in a wide range of other system components. These include Accessibility, AirDrop, App Store, AVEVideoEncoder, Contacts, CoreAudio, CoreMedia, Foundation, ImageIO, IOSkywalkFamily, Maps, MediaRemote, Model I/O, SceneKit, Siri, and WebRTC.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Apple released security updates for macOS, iOS, and iPadOS to fix dozens of vulnerabilities, primarily in the WebKit browser engine. These patches are important for user security, as the flaws could lead to crashes, data disclosure, and arbitrary code execution.