Following the release of iOS 26.6, iPadOS 26.6, and related software updates, Apple has detailed a huge number of security fixes included in today’s new OS versions.
Apple security updates in iOS 26.6 and iPadOS 26.6 impact iPhone and iPad in several ways
Across iOS 26.6 and iPadOS 26.6, Apple details more than 75 security fixes for iPhone and iPad. These fixes cover a broad range of parts of the system.
More precisely, Apple’s advisory contains 78 individual vulnerability entries tied to 87 unique CVE numbers. The CVE count is higher because several entries address more than one CVE.
Apple does not say that any of the vulnerabilities fixed in iOS 26.6 were actively exploited in the wild.
Several of the fixes stand out among Apple’s lengthy list:
- A MediaRemote flaw could let an app gain root privileges.
- An AVEVideoEncoder vulnerability could let an app execute arbitrary code with kernel privileges.
- Vulnerabilities in Game Center and libc could let a malicious app escape its sandbox.
- A CloudAttestation flaw could let a malicious app bypass code-signing enforcement.
- An ImageIO vulnerability could lead to arbitrary code execution when processing a maliciously crafted image.
- Three SceneKit vulnerabilities could lead to arbitrary code execution when processing maliciously crafted files.
- An Accessibility issue could expose sensitive data through iPhone Mirroring to someone with physical access.
- A Contacts flaw could let an app add contacts without the user’s permission.
Kernel, WebKit, and Wi-Fi fixes
Apple also fixed more than a dozen kernel vulnerabilities. The potential impacts included corrupting or writing to kernel memory, disclosing kernel memory, bypassing network filters, and causing unexpected system termination.
WebKit received a sizable collection of fixes as well. Those vulnerabilities could expose process memory, reveal whether a user had visited a link, enable interface spoofing, violate iframe sandboxing rules, let an app read files outside its sandbox, or crash Safari.
One additional Wi-Fi vulnerability could allow a nearby attacker to corrupt process memory.
After the 78 documented security fixes, Apple provides a separate “Additional recognition” section with 12 acknowledgments.
Those entries credit researchers for their assistance but are not presented as separate security fixes or assigned additional CVE numbers.
The complete list of fixes and researcher credits is available on Apple’s website.
Apple previously shared that it accelerated the released of a number of security fixes for last month’s iOS 26.5.2 release due to AI-powered hacking tools.
Do more with your Apple products