Published · 5d agoProduct3 min read
Apple's 29 fresh CVEs are unexploited, which is exactly why the clock started Monday
iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 close 29 flaws with no known attacks. Publication is the trigger event, and 21 of the 29 sit in WebKit.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- On Monday, Apple released iOS 26.6.1, iPadOS 26.6.1 and macOS 26.6.2 with fixes for 29 vulnerabilities.
- None of the 29 vulnerabilities is reported as having been exploited by hackers.
- Now that the vulnerabilities have been made public, attackers could target devices still running earlier versions of the software.
- Of the 29 CVEs outlined in Apple's security support document, 21 are WebKit-related.
- WebKit accounts for about 72 percent of the CVEs in the release.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Apple shipped iOS 26.6.1, iPadOS 26.6.1 and macOS 26.6.2 on Monday with fixes for 29 vulnerabilities, none of them reported as exploited by attackers [1][2]. That absence is the reason to move now rather than after the iOS 27 rollout: as MacRumors notes, now that the vulnerabilities are public, attackers can target devices still running earlier versions of the software [3].
The shape of the batch matters for how you triage it. Of the 29 CVEs in Apple's document, 21 are WebKit-related [4], roughly 72 percent of the release [5], and Apple says malicious web content could crash Safari or corrupt memory in most of those cases [6]. Add a trio of kernel flaws, where Apple warns a remote attacker or malicious app could terminate the system or corrupt memory [7], an audio bug that could let an app leak sensitive user information [8], and, on iOS, a telephony bug that could let an attacker in a privileged network position bypass IPSec authentication and intercept network traffic [9]. Those categories plus the image flaw account for 27 of the 29 [10].
Adam Boynton, senior enterprise strategy manager at Jamf, told ZDNET the standout fix is CVE-2026-65346, an integer overflow in ImageIO, Apple's framework for decoding images, and that exploiting it could let an attacker write memory where they should not and gain code execution [11]. That is the one that does not require a user to visit a hostile page in the way a WebKit bug does.
The fleet problem is on the older end. Apple also released iOS 18.7.10 and iPadOS 18.7.10 for devices that cannot run iOS 26, carrying the same security fixes plus patches for other flaws [12]. Macs are worse off: MacRumors reports Apple did not ship macOS Sequoia or macOS Sonoma updates for machines that cannot run macOS Tahoe [13]. Boynton's point about the iPhone XS era applies here too, that exploit research consistently shows attackers reusing known vulnerabilities against older software long after current hardware is patched [14].
On cadence, this is Apple's third security release in three weeks, which MacRumors attributes to AI surfacing bugs faster than the company's usual release schedule can absorb [15]. Nine of the 29 flaws are credited to OpenAI's Codex Security [16], about 31 percent of the release [17]. ZDNET discloses that its parent company, Ziff Davis, filed an April 2025 lawsuit against OpenAI alleging infringement of Ziff Davis copyrights in training and operating its AI systems [18]. The trend line is visible regardless: iOS 26.6 in late July fixed 91 vulnerabilities [19], and iOS 25.2 in late June patched 29 [20]. According to 9to5Mac, Apple has recently suggested it will ship security fixes more regularly because of the increased risk of AI-powered hacking attempts [21].
Two things to watch. First, visionOS 26.6.1 also shipped, but 9to5Mac reports Apple's security notes for it were still marked coming soon [22], so headset fleets are patching without a published list. Second, Apple says these fixes were previously added to the iOS 27, iPadOS 27 and macOS Golden Gate betas [23], and iOS 27 is expected in mid-September [24], which means beta channels were carrying the fixes while production devices waited. Installation is the usual path: Settings, General, Software Update on iPhone and iPad, and System Settings on a Mac [25].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On Monday, Apple released iOS 26.6.1, iPadOS 26.6.1 and macOS 26.6.2 with fixes for 29 vulnerabilities.
ReportedView cited source - [2]
None of the 29 vulnerabilities is reported as having been exploited by hackers.
ReportedView cited source - [3]
Now that the vulnerabilities have been made public, attackers could target devices still running earlier versions of the software.
- [4]
Of the 29 CVEs outlined in Apple's security support document, 21 are WebKit-related.
ReportedView cited source - [6]
Most of the vulnerabilities affect WebKit, Apple's browser engine, and Apple says malicious web content could crash Safari or corrupt memory.
ReportedView cited source - [7]
Three of the flaws affect the operating system kernel, with warnings that a remote attacker or a malicious app could terminate the system or corrupt memory.
ReportedView cited source
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- 9to5mac.comRyan Christoffel6d agoApple releases iOS 26.6.1 for iPhone, here’s what’s new
- 9to5mac.comRyan Christoffel6d agoiOS 26.6.1 has fixes for 20+ security issues on iPhone, details here
- macrumors.comJuli Clover6d ago



