Dozens of WebKit Vulnerabilities Patched in New macOS and iOS Security Updates
Apple released updated versions of macOS, iOS, and iPadOS to resolve multiple security flaws, with a significant number impacting the WebKit browser engine.
macOS Tahoe 26.6.2 Security Fixes
The latest macOS Tahoe 26.6.2 update addresses 28 vulnerabilities, including 21 in WebKit that could trigger Safari or process crashes, memory corruption, and exposure of sensitive data. Additional fixes target seven issues in Audio, ImageIO, IOGPUFamily, and Kernel components, which could enable unauthorized access to user information, denial-of-service attacks, arbitrary code execution, memory corruption, system termination, and kernel memory disclosure or modification.
iOS and iPadOS 26.6.1 Patches
iOS 26.6.1 and iPadOS 26.6.1 received identical patches for the 28 vulnerabilities, along with a resolution for an authentication flaw in Telephony that might allow adversaries to circumvent IPSec authentication and intercept network traffic. These updates are seen as preparatory steps for the upcoming iOS 27 and iPadOS 27 releases, anticipated later this month.
Patches for iOS 18.7.10 and iPadOS 18.7.10
Apple issued patches for iOS 18.7.10 and iPadOS 18.7.10, addressing over 120 bugs, including more than 40 in WebKit. These flaws could cause crashes, memory corruption, data exposure, sandbox escapes, and cross-origin data exfiltration. The Kernel component also saw 18 vulnerabilities resolved, which could lead to kernel memory corruption, system crashes, kernel memory disclosure, bypassing network filters, kernel memory writes, leakage of sensitive kernel states, and unauthorized access to user data.
Broader Security Fixes Across System Components
Security fixes were implemented across multiple system components, including Accessibility, AirDrop, App Store, AVEVideoEncoder, Contacts, CoreAudio, CoreMedia, Foundation, ImageIO, IOSkywalkFamily, Maps, MediaRemote, Model I/O, SceneKit, Siri, WebRTC, and others. Apple has not confirmed any of these vulnerabilities being actively exploited in real-world attacks, but users are strongly encouraged to apply the updates promptly.
Context and Recommendations
The release coincides with ongoing efforts to address critical vulnerabilities in third-party software, including recent reports of exploits targeting unpatched GeoServer instances and Adobe Commerce flaws. Additionally, enterprise users are advised to monitor developments around emerging threats, such as the AmnesiaStealer macOS malware and vulnerabilities in DevSecOps tools. Apple’s security updates highlight the continuous need for proactive patch management, as unresolved flaws in browser engines and system kernels remain prime targets for malicious actors seeking to compromise device integrity and user data. Organizations are urged to prioritize deployment of these patches to mitigate potential risks associated with the identified vulnerabilities.
