After the release of iOS 26.6, iPadOS 26.6, and other related software updates, Apple has unveiled a significant number of security fixes included in the latest OS versions.
Apple security updates in iOS 26.6 and iPadOS 26.6 impact iPhone and iPad in several ways
Apple has outlined over 75 security fixes for iPhone and iPad in iOS 26.6 and iPadOS 26.6, covering various parts of the system.
Apple’s advisory includes 78 individual vulnerability entries associated with 87 unique CVE numbers. Some entries address multiple CVEs, resulting in a higher CVE count.
Apple has not indicated that any of the vulnerabilities addressed in iOS 26.6 were exploited in real-world scenarios.
Several notable fixes from Apple’s extensive list include:
- A MediaRemote flaw that could enable an app to obtain root privileges.
- An AVEVideoEncoder vulnerability that could allow an app to execute arbitrary code with kernel privileges.
- Vulnerabilities in Game Center and libc that could enable a malicious app to escape its sandbox.
- A CloudAttestation flaw that could permit a malicious app to bypass code-signing enforcement.
- An ImageIO vulnerability that could result in arbitrary code execution when processing a malicious image.
- Three SceneKit vulnerabilities that could lead to arbitrary code execution when processing malicious files.
- An Accessibility issue that could expose sensitive data through iPhone Mirroring to a physical intruder.
- A Contacts flaw that could allow an app to add contacts without user permission.
Kernel, WebKit, and Wi-Fi fixes
Apple has also addressed more than a dozen kernel vulnerabilities, with potential impacts including memory corruption, disclosure, network filter bypass, and system termination.
WebKit has received a significant number of fixes, addressing vulnerabilities that could expose process memory, reveal link visit history, enable interface spoofing, violate iframe sandboxing, read files outside the sandbox, or crash Safari.
Additionally, a Wi-Fi vulnerability could allow nearby attackers to corrupt process memory.
In addition to the 78 security fixes, Apple has provided a section for “Additional recognition” with 12 acknowledgments for researchers’ assistance, though these are not separate security fixes or assigned additional CVE numbers.
For the complete list of fixes and researcher credits, visit Apple’s website.
Security fixes for Mac, Apple Watch, Apple TV, and Apple Vision Pro
Apple’s macOS Tahoe 26.6 security notes list 155 unique CVEs, addressing vulnerabilities shared with iPhone and iPad as well as specific Mac-related issues.
The Mac update tackles vulnerabilities that could grant root access, sandbox escape, Gatekeeper bypass, privacy preferences bypass, and data access.
Updates for watchOS 26.6, tvOS 26.6, and visionOS 26.6 address 194 unique CVEs after removing overlaps between platforms.
Apple previously mentioned expediting security fixes in the iOS 26.5.2 release due to the threat of AI-powered hacking tools.

FTC: We use income earning auto affiliate links. More.