HeadlinesBriefing favicon HeadlinesBriefing.com

iOS 26.6: 75+ Security Fixes Released

9to5Mac •
×

Apple has released iOS 26.6, iPadOS 26.6, and other software updates, addressing a significant number of security vulnerabilities. The updates collectively include 78 individual vulnerability entries, linked to 87 unique CVE numbers, patching a wide range of system components.

While Apple has not confirmed any of these vulnerabilities were actively exploited, several are noteworthy. These include flaws in Media Remote (allowing root privileges), AVEVideo Encoder (arbitrary code execution with kernel privileges), Game Center and libc (sandbox escape), Cloud Attestation (bypassing code-signing), Image IO (arbitrary code execution), Scene Kit (arbitrary code execution), Accessibility (data exposure), and Contacts (unauthorized contact addition).

The updates also address over a dozen kernel vulnerabilities, potentially impacting memory integrity and system stability. WebKit received numerous fixes, affecting process memory, link history, interface spoofing, sandboxing, file access, and Safari stability. A Wi-Fi vulnerability could also allow a nearby attacker to corrupt process memory. In addition to the documented fixes, Apple provided 12 acknowledgments to researchers for their contributions.