Advertisement

iPhone Update Gets 87 Security Patches, Your Mac Got Nearly Twice That: Update ASAP

Laptop By Ayush Mukherjee
Last Updated: 2026-07-28 11:32:29
SHARE
Facebook
Facebook

Most software updates get judged by their feature list. This one should be judged by what it closes off. Apple’s newest round of updates, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, and their companion releases for Watch, TV, and Vision Pro, patches 194 unique security vulnerabilities once duplicates across platforms are stripped out. None were reported as actively exploited before the fix, but that’s exactly the window this update closes.

The scale, by device

iPhone and iPad share the smaller of the two major patch sets: 78 individual vulnerability entries, covering 87 distinct CVEs (some entries fix more than one CVE at once, which is why the CVE count runs higher than the entry count).

Mac owners have more catching up to do. macOS Tahoe 26.6 alone accounts for 155 unique CVEs, nearly double the iPhone and iPad total. Apple also quietly shipped matching security-only updates for older, still-supported macOS versions today, so Mac users not yet on Tahoe aren’t left exposed either, though those releases sit outside the 155 figure. Round out the picture with watchOS, tvOS, and visionOS, and the combined total across every platform lands at 194 unique CVEs.

Related Articles

The fixes that actually matter to you

Strip away the technical jargon, and the patched vulnerabilities generally fall into three practical buckets: flaws that could hand an app more control than it should ever have, flaws that could run malicious code just from you opening a file, and flaws that could quietly leak data you’d assume was private.

Apps grabbing more power than they should. A MediaRemote bug could have let an app claim root privileges, effectively full control of the device. Separate flaws in Game Center and libc could have let a malicious app break out of its sandbox entirely, the isolated environment every app is supposed to be trapped inside. A CloudAttestation issue could have let an app slip past Apple’s code-signing checks altogether.

Malicious files doing damage on their own. An AVEVideoEncoder vulnerability could have triggered arbitrary code execution with kernel-level privileges, about as severe as it gets, and it didn’t require you to do anything unusual to trigger it. An ImageIO flaw meant a booby-trapped image alone could execute code the moment it was processed. Three separate SceneKit bugs carried the same risk through crafted files.

Data leaking where it shouldn’t. An Accessibility flaw could expose sensitive information through iPhone Mirroring to anyone with physical access to your device. A Contacts bug could let an app silently add new contacts without ever asking your permission. And a Wi-Fi vulnerability meant an attacker simply within range, not even on your network, could corrupt process memory on a nearby device.

The invisible layer: kernel and WebKit

Beneath all of that sits the update’s biggest single category: more than a dozen kernel-level fixes, covering everything from corrupting or leaking kernel memory to bypassing network filters or crashing the system outright. WebKit, the engine powering Safari and every in-app browser view, received a similarly large batch, closing issues that could expose process memory, reveal your browsing history to a malicious site, spoof interface elements, break sandbox rules between iframes, or let an app read files it had no business accessing.

Apple also credited 12 researchers in a separate “Additional recognition” section for the release, contributors who helped without their findings being tied to a specific standalone CVE. The full technical writeup, including every researcher credit, sits on Apple’s own security releases page for anyone who wants the granular detail.

This isn’t a one-off. Last month, Apple pulled a batch of fixes forward into iOS 26.5.2 ahead of its normal schedule, citing concern that AI-assisted tools are shortening the gap between a vulnerability becoming known and someone building a working exploit for it. Coverage from Apple-focused outlet TidBITS also notes it wouldn’t be surprising to see Apple extend some of these WebKit fixes to older macOS versions through a standalone Safari update, and possibly bring select patches to the small pool of devices still stuck on iOS 18, like the iPhone XS and XR, which can’t run iOS 26 at all. Read together, the pattern points to Apple treating patch speed itself as a competitive necessity now, not just a routine maintenance cycle.

Given how many of these fixes touch the kernel, WebKit, and app sandboxing specifically, on both iPhone and Mac, this is worth installing today rather than letting it sit. On iPhone or iPad, go to Settings, then General, then Software Update. On Mac, it’s System Settings, then General, then Software Update. The protection these patches offer only counts once they’re actually installed on your device.

Latest News