Skip to content

Product3 publishers3 min readPublished Updated

Apple's 29 fresh CVEs are unexploited, which is exactly why the clock started Monday

iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 close 29 flaws with no known attacks. Publication is the trigger event, and 21 of the 29 sit in WebKit.

The Product Desk · Product desk

Photograph accompanying Apple's 29 fresh CVEs are unexploited, which is exactly why the clock started Monday
Photo: techrepublic.com

What happened

  • On Monday, Apple released iOS 26.6.1, iPadOS 26.6.1 and macOS 26.6.2 with fixes for 29 vulnerabilities.
  • None of the 29 vulnerabilities is reported as having been exploited by hackers.
  • Now that the vulnerabilities have been made public, attackers could target devices still running earlier versions of the software.
  • Of the 29 CVEs outlined in Apple's security support document, 21 are WebKit-related.
  • WebKit accounts for about 72 percent of the CVEs in the release.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

Apple shipped iOS 26.6.1, iPadOS 26.6.1 and macOS 26.6.2 on Monday with fixes for 29 vulnerabilities, none of them reported as exploited by attackers [1][2]. That absence is the reason to move now rather than after the iOS 27 rollout: as MacRumors notes, now that the vulnerabilities are public, attackers can target devices still running earlier versions of the software [3].

The shape of the batch matters for how you triage it. Of the 29 CVEs in Apple's document, 21 are WebKit-related [4], roughly 72 percent of the release [5], and Apple says malicious web content could crash Safari or corrupt memory in most of those cases [6]. Add a trio of kernel flaws, where Apple warns a remote attacker or malicious app could terminate the system or corrupt memory [7], an audio bug that could let an app leak sensitive user information [8], and, on iOS, a telephony bug that could let an attacker in a privileged network position bypass IPSec authentication and intercept network traffic [9]. Those categories plus the image flaw account for 27 of the 29 [10].

Adam Boynton, senior enterprise strategy manager at Jamf, told ZDNET the standout fix is CVE-2026-65346, an integer overflow in ImageIO, Apple's framework for decoding images, and that exploiting it could let an attacker write memory where they should not and gain code execution [11]. That is the one that does not require a user to visit a hostile page in the way a WebKit bug does.

The fleet problem is on the older end. Apple also released iOS 18.7.10 and iPadOS 18.7.10 for devices that cannot run iOS 26, carrying the same security fixes plus patches for other flaws [12]. Macs are worse off: MacRumors reports Apple did not ship macOS Sequoia or macOS Sonoma updates for machines that cannot run macOS Tahoe [13]. Boynton's point about the iPhone XS era applies here too, that exploit research consistently shows attackers reusing known vulnerabilities against older software long after current hardware is patched [14].

On cadence, this is Apple's third security release in three weeks, which MacRumors attributes to AI surfacing bugs faster than the company's usual release schedule can absorb [15]. Nine of the 29 flaws are credited to OpenAI's Codex Security [16], about 31 percent of the release [17]. ZDNET discloses that its parent company, Ziff Davis, filed an April 2025 lawsuit against OpenAI alleging infringement of Ziff Davis copyrights in training and operating its AI systems [18]. The trend line is visible regardless: iOS 26.6 in late July fixed 91 vulnerabilities [19], and iOS 25.2 in late June patched 29 [20]. According to 9to5Mac, Apple has recently suggested it will ship security fixes more regularly because of the increased risk of AI-powered hacking attempts [21].

Two things to watch. First, visionOS 26.6.1 also shipped, but 9to5Mac reports Apple's security notes for it were still marked coming soon [22], so headset fleets are patching without a published list. Second, Apple says these fixes were previously added to the iOS 27, iPadOS 27 and macOS Golden Gate betas [23], and iOS 27 is expected in mid-September [24], which means beta channels were carrying the fixes while production devices waited. Installation is the usual path: Settings, General, Software Update on iPhone and iPad, and System Settings on a Mac [25].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories