started · updated
Apple releases iOS 26.6.1 and macOS updates to patch critical security flaws
Apple has released a series of critical security updates, including iOS 26.6.1, iPadOS 26.6.1, visionOS 26.6.1, and macOS Tahoe 26.6.2, to address approximately 30 vulnerabilities. The updates are primarily focused on security patches rather than new features, serving as a final major maintenance cycle before the anticipated release of iOS 27.
A significant portion of the fixes—roughly 21 vulnerabilities—targets the WebKit engine, which powers the Safari browser. These flaws could lead to memory corruption, unexpected system crashes, or the leakage of sensitive data. Additionally, the updates address critical issues in the ImageIO framework, such as CVE-2026-65346, which could allow arbitrary code execution via specially crafted images, and the Kernel, which could enable unauthorized memory access.
Another notable fix involves a Telephony vulnerability (CVE-2026-65329) that could allow attackers to bypass IPSec authentication and intercept network traffic. Nine of the identified WebKit vulnerabilities were discovered by researchers using OpenAI Codex Security. While these flaws are serious, there is currently no evidence that they have been exploited in the wild. Apple also released iOS 18.7.10 and iPadOS 18.7.10 to provide security support for older compatible devices.
Entities
Apple · Cisco Talos · OpenAI · OpenAI Codex Security · Safari · WebKit · iOS · iPhone · iPhone · macOS Tahoe
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] iOS 18.7.10 and iPadOS 18.7.10 were released for older devices that cannot run iOS 26. timesng.com · www.icreatemagazine.nl · www.itmedia.co.jp · www.itopnews.de
- [DISPUTED] The updates address approximately 29 security vulnerabilities. www.t-online.de · timesng.com · www.chip.com.tr · www.itmedia.co.jp · www.uagna.it · +1 more
- [● 4 SOURCES] The update fixes an ImageIO flaw (CVE-2026-65346) that could lead to arbitrary code execution. www.mobilebit.com.br · cybernoz.com · timesng.com · www.itmedia.co.jp
- [● 6 SOURCES] The updates do not include new features and focus primarily on security patches. www.mobilebit.com.br · www.theasianaffairs.com · mrmad.com.tw · www.t-online.de · www.spacemoney.com.br · +1 more
- [● 8 SOURCES] Nine of the vulnerabilities were identified by researchers using OpenAI Codex Security. cybernoz.com · www.iphonote.com · www.chip.com.tr · www.itmedia.co.jp · timesng.com · +1 more
- [● 13 SOURCES] 21 of the addressed vulnerabilities are located in the WebKit engine. www.t-online.de · timesng.com · www.chip.com.tr · www.itmedia.co.jp · www.uagna.it · +6 more
- [● 4 SOURCES] The update fixes a Telephony flaw (CVE-2026-65329) that could allow interception of network traffic. www.mobilebit.com.br · www.spacemoney.com.br · www.chip.com.tr · www.itmedia.co.jp
- [● 24 SOURCES] Apple released iOS 26.6.1, iPadOS 26.6.1, visionOS 26.6.1, and macOS Tahoe 26.6.2. www.mobilebit.com.br · www.theasianaffairs.com · cybernoz.com · mrmad.com.tw · www.t-online.de · +17 more
- [● 6 SOURCES] CVE-2026-65346 is an ImageIO vulnerability that could allow arbitrary code execution. www.mobilebit.com.br · cybernoz.com · timesng.com · www.itmedia.co.jp · congnghe.vn · +1 more
- [● 4 SOURCES] OpenAI Codex Security identified nine of the vulnerabilities. cybernoz.com · www.iphonote.com · www.chip.com.tr · www.itmedia.co.jp
- [● 2 SOURCES] CVE-2026-65329 allows bypassing IPSec authentication to intercept network traffic. www.mobilebit.com.br · www.spacemoney.com.br
- [● 5 SOURCES] iOS 18.7.10 and iPadOS 18.7.10 were released for older devices. timesng.com · www.icreatemagazine.nl · www.itmedia.co.jp · www.itopnews.de · cybernoz.com