Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS
Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application crashes, kernel memory access, and arbitrary code execution.
The updates were released on August 17, 2026, and include macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and iPadOS 18.7.10. The company said the patches include fixes that were previously delivered through iOS, iPadOS, and macOS beta releases.
Apple follows a policy of withholding technical details about security flaws until it completes an investigation and security updates are broadly available.
Several flaws affect components that process media, web content, and graphics. Apple fixed an integer overflow in ImageIO that could allow a specially crafted image to trigger arbitrary code execution. A separate ImageIO issue could cause a denial-of-service condition when a vulnerable device processes a malicious image.
Apple Fixes 28 Security Vulnerabilities
The updates also address multiple issues in IOGPUFamily, an Apple graphics framework. Apple warned that malicious web content could cause memory corruption.
At the same time, other flaws could enable remote attackers to terminate a system unexpectedly or allow a local application to read kernel memory. Such bugs are significant because the kernel runs with high privileges and controls core operating-system functions.
An additional kernel-level issue in the older iOS 18.7.10 and iPadOS 18.7.10 releases could allow a malicious application to execute arbitrary code with kernel privileges via a buffer overflow. Apple resolved the flaw through improved size validation.
Apple patched an Audio logic issue that could allow an application to leak sensitive user information. The company addressed the problem by adding improved checks. This vulnerability affects both macOS Tahoe 26.6.2 and the newer iOS and iPadOS releases.
The mobile updates also include an Accessibility fix for devices running iOS 18.7.10 and iPadOS 18.7.10. Apple said an attacker with physical access could potentially access sensitive data during iPhone Mirroring. This feature links an iPhone with a Mac. The issue was fixed through improved state management.
| CVE | Component | Affected release(s) | Impact | Vulnerability type / remediation |
|---|---|---|---|---|
| CVE-2026-65339 | Audio | iOS/iPadOS 26.6.1; macOS Tahoe 26.6.2 | An app may leak sensitive user information | Logic issue; improved checks |
| CVE-2026-65347 | ImageIO | iOS/iPadOS; macOS | Processing an image may cause DoS | Improved checks |
| CVE-2026-65346 | ImageIO | iOS/iPadOS; macOS | Processing an image may enable arbitrary code execution | Integer overflow; improved input validation |
| CVE-2026-64788 | IOGPUFamily | iOS/iPadOS; macOS | Crafted web content may cause memory corruption | Improved memory handling |
| CVE-2026-65343 | Kernel | iOS/iPadOS; macOS | Remote attacker may terminate the system | Use-after-free; improved memory management |
| CVE-2026-65349 | Kernel | iOS/iPadOS; macOS | App may terminate the system or read kernel memory | Out-of-bounds read; improved input validation |
| CVE-2026-65330 | Kernel | iOS/iPadOS; macOS | App may terminate the system or corrupt kernel memory | Improved memory handling |
| CVE-2026-65329 | Telephony | iOS 26.6.1 only; iPhone 11 and later | Privileged network attacker may bypass IPSec authentication and intercept traffic | Authentication issue; improved state management |
| CVE-2026-64784 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Out-of-bounds access; improved bounds checking |
| CVE-2026-43795 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved memory handling |
| CVE-2026-65338 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved memory handling |
| CVE-2026-65341 | WebKit | iOS/iPadOS; macOS | Crafted web content may cause memory corruption | Improved memory handling |
| CVE-2026-64782 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Memory-corruption flaw; improved locking |
| CVE-2026-64781 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved input validation |
| CVE-2026-65351 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65340 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65337 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65336 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65335 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65333 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65332 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-65331 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved state management |
| CVE-2026-64715 | WebKit | iOS/iPadOS; macOS | Crafted web content may cause an unexpected process crash | Use-after-free; improved memory management |
| CVE-2026-64780 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Improved checks |
| CVE-2026-65334 | WebKit | iOS/iPadOS; macOS | Crafted web content may crash Safari | Memory-corruption flaw; improved state management |
| CVE-2026-43794 | WebKit | iOS/iPadOS; macOS | Crafted web content may cause memory corruption | Memory-corruption flaw; improved memory handling |
| CVE-2026-64787 | WebKit | iOS/iPadOS; macOS | Crafted web content may terminate a process | Use-after-free; improved memory management |
| CVE-2026-64778 | WebKit History | iOS/iPadOS; macOS | Visiting a crafted website may leak sensitive data | Improved checks |
| CVE-2026-64779 | WebKit Storage | iOS/iPadOS; macOS | Crafted web content may crash Safari | Memory-corruption flaw; improved locking |
Apple also corrected an IPSec authentication issue in iOS 26.6.1 and iPadOS 26.6.1. A threat actor in a privileged network position could bypass IPSec authentication and intercept network traffic, posing a risk to users on hostile or compromised networks.
iOS 26.6.1 and iPadOS 26.6.1 are available for iPhone 11 and later, supported iPad Pro models, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
The iOS 18.7.10 and iPadOS 18.7.10 updates protect older iPhone XS, iPhone XS Max, iPhone XR, and iPad 7th-generation devices. Users should install the updates promptly. Apple notes that iPhone, iPad, Apple TV, Apple Watch, and Vision Pro software cannot be downgraded after an update is installed.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS appeared first on Cyber Security News.


