Illustrative image generated with AI
Apple Updates macOS, iOS, and iPadOS: Dozens of WebKit, Kernel, and Networking Flaws Fixed
Apple patches critical flaws in macOS, iOS, iPadOS addressing WebKit, kernel, and networking issues to prevent crashes and data leaks.
Text generated by artificial intelligence, published without human review. AI transparency
A New Round of Patches for Apple Operating Systems
On August 18, 2026, Apple released a new round of security updates for macOS, iOS, and iPadOS. Most of the fixes address WebKit, the engine behind Safari, but the updates also cover system components with access to memory, communications, and the kernel.
The reported impacts include crashes, memory corruption, sensitive information disclosure, sandbox escapes, cross-origin data exfiltration, and arbitrary code execution. Some vulnerabilities could also compromise kernel memory or allow access to confidential user data.
Apple has not stated that these flaws have been exploited in real-world attacks. However, the lack of confirmation does not reduce the priority of these updates: WebKit is exposed during web browsing, while the kernel and networking components operate at highly privileged system levels.
macOS Tahoe 26.6.2 Fixes 28 Vulnerabilities
The macOS Tahoe 26.6.2 update resolves 28 vulnerabilities in total. Of these, 21 affect WebKit and could cause Safari or related processes to crash, corrupt memory, or disclose sensitive information.
A memory-safety flaw in a rendering engine can be particularly dangerous when triggered through a web page, embedded content, or a malicious advertisement. The brief does not identify a specific attack chain or confirm that these flaws can automatically lead to code execution. However, the stated impacts remain consistent with scenarios extending beyond a simple browser crash.
The remaining seven vulnerabilities affect Audio, ImageIO, IOGPUFamily, and Kernel. Potential impacts include:
- information disclosure;
- denial of service;
- arbitrary code execution;
- memory corruption;
- system termination or instability;
- exposure or modification of kernel memory.
Kernel and IOGPUFamily are particularly sensitive components because they handle core operating system and hardware functions. A successful attack at these levels could provide broader capabilities than compromising a single application.
iOS 26.6.1 and iPadOS 26.6.1 Add a Telephony Issue
iOS 26.6.1 and iPadOS 26.6.1 include the same 28 fixes shipped in macOS Tahoe 26.6.2. However, the mobile operating systems also receive an additional patch for the Telephony component.
The vulnerability could allow an attacker to bypass IPSec authentication and intercept network traffic. IPSec protects communications through authentication and encryption mechanisms; bypassing authenticity checks could therefore expose traffic to interception or manipulation, depending on the configuration and operating environment.
The brief does not specify which iPhone or iPad models are affected, nor does it describe the conditions required for exploitation. It is therefore impossible to determine whether an attack requires local network access, a privileged position, or other specific circumstances.
These versions also appear to prepare the transition to the next major iOS and iPadOS releases, expected next month. For users who remain on version 26, however, installing this security update remains the recommended way to address the disclosed flaws.
The iOS 18 Line Receives More Than 120 Fixes
Apple also released iOS 18.7.10 and iPadOS 18.7.10 for devices running the previous mobile operating system line. These updates address more than 120 vulnerabilities, including over 40 WebKit issues.
Impacts include crashes, memory corruption, data disclosure, sandbox escapes, and cross-origin information exfiltration. The latter refers to the possibility of obtaining data belonging to separate web contexts, violating the boundaries that prevent one website from freely reading another website’s information.
The sandbox limits what a process can do even after it has been compromised. Escaping the sandbox can therefore turn a browser-level vulnerability into a broader security issue, particularly when it enables access to files, processes, or services that should remain isolated.
The iOS 18 updates also fix 18 Kernel vulnerabilities. Some could allow attackers to corrupt or write to kernel memory, crash the system, disclose sensitive kernel memory or state, bypass network filters, or access confidential user data.
Other affected components include Accessibility, AirDrop, App Store, AVEVideoEncoder, Contacts, CoreAudio, CoreMedia, Foundation, IOSkywalkFamily, Maps, MediaRemote, Model I/O, SceneKit, Siri, and WebRTC. For some of these components, insufficient technical details are available to reconstruct the attack path.
KEV Catalog and Exploitation Status
It is not known whether one or more vulnerabilities from this cycle have been added to CISA’s Known Exploited Vulnerabilities catalog. As a result, no inclusion date or specific remediation deadline under that catalog is currently available.
Apple has also not stated that the flaws have already been exploited in real-world attacks. Based on the available information, there are no known indicators of compromise, campaigns attributed to specific groups, or public exploits linked to these fixes.
It is also unknown whether Apple has had other recent entries in the KEV catalog. This makes it impossible to place the update within a documented series of actively exploited Apple vulnerabilities.
The absence of a KEV listing does not represent a favorable security assessment. Vulnerabilities combining code execution, sensitive-data access, sandbox escape, and kernel compromise warrant priority treatment, especially on devices used for business or connected to untrusted networks.
What Users and Administrators Should Do
Users should promptly install the version available for their device:
- macOS Tahoe 26.6.2;
- iOS 26.6.1;
- iPadOS 26.6.1;
- iOS 18.7.10;
- iPadOS 18.7.10.
Updates can be checked through the system’s software update settings. In enterprise environments, administrators should monitor deployment through device-management tools, prioritizing endpoints that frequently browse the web, handle sensitive data, or connect to public and untrusted networks.
Before installation, verify that backups are available and that business applications are compatible with the planned version. Relying on specific workarounds is not recommended: no alternative mitigations capable of replacing the patches have been disclosed.
Until updates are complete, users should limit browsing to untrusted websites and avoid opening content received from unknown sources. These measures reduce exposure but do not fix the vulnerabilities; effective protection still requires installing the updated versions.
Sources
This article is an original reworking based on the sources below.
