Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
None of the vulnerabilities has been exploited so far. There are a few WebKit vulnerabilities, but no standalone Safari patch for older operating systems. 87 of the vulnerabilities affect only iOS 18, making this more of an iOS 18 release than one for the newer operating systems. Only six vulnerabilities affect all three OSs released today. All 6 vulnerabilities affect WebKit.
Apple's vulnerability summary notes that the vulnerabilities patched in today's VisionOS release will be enumerated at a later date.
|
iOS 26.6.1 and iPadOS 26.6.1 |
iOS 18.7.10 and iPadOS 18.7.10 |
macOS Tahoe 26.6.2 |
|---|---|---|
|
CVE-2026-28958: An app
may be able to access sensitive user data. |
||
|
|
x |
|
|
CVE-2026-28973: A
malicious app may be able to break out of its sandbox. |
||
|
|
x |
|
|
CVE-2026-28984: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
|
x |
|
|
CVE-2026-28990: Processing
a maliciously crafted image may corrupt process memory. |
||
|
|
x |
|
|
CVE-2026-28996: An app
may be able to access sensitive user data. |
||
|
|
x |
|
|
CVE-2026-39868: An app
may be able to cause unexpected system termination or corrupt kernel
memory. |
||
|
|
x |
|
|
CVE-2026-39877: An app
may be able to disclose kernel memory. |
||
|
|
x |
|
|
CVE-2026-43661: Processing
a maliciously crafted image may corrupt process memory. |
||
|
|
x |
|
|
CVE-2026-43663: Processing
maliciously crafted web content may lead to an unexpected process
crash. |
||
|
|
x |
|
|
CVE-2026-43667: An
attacker in a privileged network position may be able to cause a
denial-of-service. |
||
|
|
x |
|
|
CVE-2026-43673: Processing
a maliciously crafted audio file may corrupt process memory. |
||
|
|
x |
|
|
CVE-2026-43676: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
|
x |
|
|
CVE-2026-43700: Processing
maliciously crafted web content may disclose sensitive user
information. |
||
|
|
x |
|
|
CVE-2026-43701: A
malicious website may be able to process restricted web content
outside the sandbox. |
||
|
|
x |
|
|
CVE-2026-43705: Processing
maliciously crafted web content may lead to memory corruption. |
||
|
|
x |
|
|
CVE-2026-43708: A
malicious website may exfiltrate data cross-origin. |
||
|
|
x |
|
|
CVE-2026-43711: Processing
a maliciously crafted video file may lead to unexpected app
termination. |
||
|
|
x |
|
|
CVE-2026-43714: A
malicious app may be able to access protected user data. |
||
|
|
x |
|
|
CVE-2026-43717: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
|
x |
|
|
CVE-2026-43720: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
|
x |
|
|
CVE-2026-43722: An app
may be able to leak sensitive kernel state. |
||
|
|
x |
|
|
CVE-2026-43723: An app
may be able to gain root privileges. |
||
|
|
x |
|
|
CVE-2026-43724: An app
may be able to cause unexpected system termination or write kernel
memory. |
||
|
|
x |
|
|
CVE-2026-43725: A
malicious website may be able to process restricted web content
outside the sandbox. |
||
|
|
x |
|
|
CVE-2026-43727: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
|
x |
|
|
CVE-2026-43729: Processing
a maliciously crafted image may corrupt process memory. |
||
|
|
x |
|
|
CVE-2026-43731: Processing
maliciously crafted web content may lead to memory corruption. |
||
|
|
x |
|
|
CVE-2026-43735: A
malicious website may exfiltrate data cross-origin. |
||
|
|
x |
|
|
CVE-2026-43738: Processing
a maliciously crafted asset catalog may result in disclosure of
process memory. |
||
|
|
x |
|
|
CVE-2026-43742: Processing
maliciously crafted web content may lead to an unexpected process
crash. |
||
|
|
x |
|
|
CVE-2026-43744: Processing
an audio stream in a maliciously crafted media file may terminate
the process. |
||
|
|
x |
|
|
CVE-2026-43745: Processing maliciously crafted web content may lead
to an unexpected Safari crash. |
||
|
|
x |
|
|
CVE-2026-43754: An app
may be able to leak sensitive kernel state. |
||
|
|
x |
|
|
CVE-2026-43757: An app
may be able to cause unexpected system termination. |
||
|
|
x |
|
|
CVE-2026-43769: An app
may be able to cause unexpected system termination. |
||
|
|
x |
|
|
CVE-2026-43776: Processing a maliciously crafted file may lead to
unexpected app termination or arbitrary code execution. |
||
|
|
x |
|
|
CVE-2026-43778: An app
may be able to cause unexpected system termination or corrupt kernel
memory. |
||
|
|
x |
|
|
CVE-2026-43794: Processing maliciously crafted web content may lead
to memory corruption. |
||
|
x |
x |
x |
|
CVE-2026-43796: An app
may be able to read a persistent device identifier. |
||
|
|
x |
|
|
CVE-2026-43797: An app
may be able to access information about a user's contacts. |
||
|
|
x |
|
|
CVE-2026-43800: An app
may be able to access sensitive user data. |
||
|
|
x |
|
|
CVE-2026-43801: An app
may be able to access sensitive user data. |
||
|
|
x |
|
|
CVE-2026-43802: An app
may be able to cause unexpected system termination. |
||
|
|
x |
|
|
CVE-2026-43803: A
remote attacker may be able to cause unexpected system termination. |
||
|
|
x |
|
|
CVE-2026-43807: A
malicious accessory may be able to cause unexpected app termination. |
||
|
|
x |
|
|
CVE-2026-43810: A
remote user may be able to cause unexpected system termination or
corrupt kernel memory. |
||
|
|
x |
|
|
CVE-2026-43811: An app
may be able to modify protected parts of the file system. |
||
|
|
x |
|
|
CVE-2026-43812: An app
may be able to cause unexpected system termination. |
||
|
|
x |
|
|
CVE-2026-43818: Processing
a maliciously crafted image may lead to arbitrary code execution. |
||
|
|
x |
|
|
CVE-2026-43821: An app
may be able to read files outside of its sandbox. |
||
|
|
x |
|
|
CVE-2026-64692: An app
may be able to cause a denial-of-service. |
||
|
|
x |
|
|
CVE-2026-64693: Processing a maliciously crafted image may lead to a
denial-of-service. |
||
|
|
x |
|
|
CVE-2026-64695: A
remote user may be able to cause unexpected system termination or
corrupt kernel memory. |
||
|
|
x |
|
|
CVE-2026-64700: An app
may be able to cause unexpected system termination. |
||
|
|
x |
|
|
CVE-2026-64707: An app
may be able to delete files for which it does not have permission. |
||
|
|
x |
|
|
CVE-2026-64709: An app
may be able to disclose kernel memory. |
||
|
|
x |
|
|
CVE-2026-64715: Processing
maliciously crafted web content may lead to an unexpected process
crash. |
||
|
x |
|
x |
|
CVE-2026-64719: Processing maliciously crafted web content may lead
to an unexpected Safari crash. |
||
|
|
x |
|
|
CVE-2026-64721: An app
may be able to access sensitive user data. |
||
|
|
x |
|
|
CVE-2026-64722: Processing
a 3D model may result in disclosure of process memory. |
||
|
|
x |
|
|
CVE-2026-64723: An app
may be able to access sensitive user data. |
||
|
|
x |
|
|
CVE-2026-64724: An
attacker on the local network may be able to cause a
denial-of-service. |
||
|
|
x |
|
|
CVE-2026-64725: An app
may be able to cause a denial-of-service. |
||
|
|
x |
|
|
CVE-2026-64726: An
attacker in physical proximity may be able to corrupt process
memory. |
||
|
|
x |
|
|
CVE-2026-64732: An
attacker with physical access may be able to access sensitive user
data during iPhone Mirroring. |
||
|
|
x |
|
|
CVE-2026-64734: Processing
a maliciously crafted contact may leak sensitive data. |
||
|
|
x |
|
|
CVE-2026-64735: A
remote attacker may be able to bypass network filters. |
||
|
|
x |
|
|
CVE-2026-64738: A
malicious app may be able to break out of its sandbox. |
||
|
|
x |
|
|
CVE-2026-64739: An
attacker may be able to cause unexpected app termination. |
||
|
|
x |
|
|
CVE-2026-64740: A
malicious app may be able to break out of its sandbox. |
||
|
|
x |
|
|
CVE-2026-64742: An app
may be able to access sensitive user data. |
||
|
|
x |
|
|
CVE-2026-64743: An app
may be able to access sensitive user data. |
||
|
|
x |
|
|
CVE-2026-64744: An app
may be able to disclose kernel memory. |
||
|
|
x |
|
|
CVE-2026-64746: An app
may be able to add contacts without user authorization. |
||
|
|
x |
|
|
CVE-2026-64747: An app
may be able to execute arbitrary code with kernel privileges. |
||
|
|
x |
|
|
CVE-2026-64749: An app
may be able to cause unexpected system termination or corrupt kernel
memory. |
||
|
|
x |
|
|
CVE-2026-64755: An app
may be able to access sensitive user data. |
||
|
|
x |
|
|
CVE-2026-64757: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
|
x |
|
|
CVE-2026-64760: An app
may be able to leak sensitive kernel state. |
||
|
|
x |
|
|
CVE-2026-64762: An app
may be able to cause unexpected system termination. |
||
|
|
x |
|
|
CVE-2026-64763: Processing
a maliciously crafted file may lead to unexpected app termination or
arbitrary code execution. |
||
|
|
x |
|
|
CVE-2026-64764: Processing
a maliciously crafted file may lead to unexpected app termination or
arbitrary code execution. |
||
|
|
x |
|
|
CVE-2026-64765: Processing
a maliciously crafted file may lead to unexpected app termination or
arbitrary code execution. |
||
|
|
x |
|
|
CVE-2026-64768: A
remote attacker may cause an unexpected app termination. |
||
|
|
x |
|
|
CVE-2026-64769: A
remote attacker may be able to cause unexpected application
termination or heap corruption. |
||
|
|
x |
|
|
CVE-2026-64771: A
remote attacker may be able to cause unexpected application
termination or heap corruption. |
||
|
|
x |
|
|
CVE-2026-64772: A
remote attacker may be able to cause unexpected application
termination or heap corruption. |
||
|
|
x |
|
|
CVE-2026-64774: A
remote attacker may be able to cause unexpected application
termination or heap corruption. |
||
|
|
x |
|
|
CVE-2026-64778: Visiting
a maliciously crafted website may leak sensitive data. |
||
|
x |
x |
x |
|
CVE-2026-64779: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
x |
x |
x |
|
CVE-2026-64780: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
x |
x |
x |
|
CVE-2026-64781: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
x |
x |
x |
|
CVE-2026-64782: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
x |
x |
x |
|
CVE-2026-64784: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
x |
|
x |
|
CVE-2026-64787: Processing
maliciously crafted web content may lead to an unexpected process
termination. |
||
|
x |
|
x |
|
CVE-2026-64788: Processing
maliciously crafted web content may lead to memory corruption. |
||
|
x |
|
x |
|
CVE-2026-65329: An
attacker in a privileged network position may be able to bypass
IPSec authentication and intercept network traffic. |
||
|
x |
|
|
|
CVE-2026-65330: An app
may be able to cause unexpected system termination or corrupt kernel
memory. |
||
|
x |
|
x |
|
CVE-2026-65331: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
x |
|
x |
|
CVE-2026-65334: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
x |
|
x |
|
CVE-2026-65338: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
x |
|
x |
|
CVE-2026-65339: An app
may be able to leak sensitive user information. |
||
|
x |
|
x |
|
CVE-2026-65340: Processing
maliciously crafted web content may lead to an unexpected Safari
crash. |
||
|
|
x |
|
|
CVE-2026-65341: Processing
maliciously crafted web content may lead to memory corruption. |
||
|
x |
x |
x |
|
CVE-2026-65343: A
remote attacker may be able to cause unexpected system termination. |
||
|
x |
|
x |
|
CVE-2026-65346: Processing
an image may lead to arbitrary code execution. |
||
|
x |
|
x |
|
CVE-2026-65347: Processing
an image may lead to a denial-of-service. |
||
|
x |
|
x |
|
CVE-2026-65349: An app
may be able to cause unexpected system termination or read kernel
memory. |
||
|
x |
|
x |