Apple on Monday released iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2. The updates fix almost 30 security vulnerabilities, according to Apple’s security support document. Apple says the software includes security fixes that were previously added to the iOS 27, iPadOS 27, and macOS Golden Gate betas.
The fixes include:
iOS 26.6.1 and iPadOS 26.6.1
Released August 17, 2026
Audio
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to leak sensitive user information
Description: A logic issue was addressed with improved checks.
CVE-2026-65339: Meta Red Team X – Nik Tsytsarkin
ImageIO
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing an image may lead to a denial-of-service
Description: The issue was addressed with improved checks.
CVE-2026-65347: Geonha Lee (@leegn4a)
ImageIO
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing an image may lead to arbitrary code execution
Description: An integer overflow was addressed with improved input validation.
CVE-2026-65346: Meta Red Team X – Nik Tsytsarkin
IOGPUFamily
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
CVE-2026-64788: f00l (@PPPF00L) and 3ndy1(@_3ndy1) and Minghao Lin@Y1nkoc and 云散花折, Arjanit Isufi
Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: A remote attacker may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory management.
CVE-2026-65343: Drinor Selmanaj (Sentry), Surya Narayan Kushwaha
Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to cause unexpected system termination or read kernel memory
Description: An out-of-bounds read was addressed with improved input validation.
CVE-2026-65349: an anonymous researcher
Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-65330: Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
Telephony
Available for: iPhone 11 and later
Impact: An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Description: An authentication issue was addressed with improved state management.
CVE-2026-65329: Bedran Karakoc, Tobias Funke, Jacopo Clark, Katharina Kohls of Ruhr University Bochum
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved bounds checking.
WebKit Bugzilla: 317632
CVE-2026-64784: Janggoon Lee of Out of Bounds, OpenAI Codex Security – Amy Burnett
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 313452
CVE-2026-43795: wwwlk
WebKit Bugzilla: 318348
CVE-2026-65338: OpenAI Codex Security – Amy Burnett
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 318405
CVE-2026-65341: Henock Habte
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption vulnerability was addressed with improved locking.
WebKit Bugzilla: 321480
CVE-2026-64782: Seonwook Kim, Shubham Chaskar, lattice, Josef Korbel
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 321484
CVE-2026-64781: Thomas Guillem
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: This issue was addressed through improved state management.
WebKit Bugzilla: 321517
CVE-2026-65351: Niels Hofmans
WebKit Bugzilla: 316996
CVE-2026-65340: Claudio Bozzato and Francesco Benvenuto of Cisco Talos, Josef Korbel (Citadelo)
WebKit Bugzilla: 317142
CVE-2026-65337: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317349
CVE-2026-65336: Josef Korbel
WebKit Bugzilla: 316723
CVE-2026-65335: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317603
CVE-2026-65333: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317450
CVE-2026-65332: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317611
CVE-2026-65331: OpenAI Codex Security – Amy Burnett
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 316347
CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 316918
CVE-2026-64780: OpenAI Codex Security – Amy Burnett
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption issue was addressed with improved state management.
WebKit Bugzilla: 316791
CVE-2026-65334: OpenAI Codex Security – Amy Burnett
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: A memory corruption issue was addressed with improved memory handling.
WebKit Bugzilla: 317317
CVE-2026-43794: Dung Do (@_piers2) of Calif.io
WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected process termination
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 313703
CVE-2026-64787: 杉山 壮太, Shubham Chaskar
WebKit History
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Visiting a maliciously crafted website may leak sensitive data
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 315528
CVE-2026-64778: Mohit Negi
WebKit Storage
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption vulnerability was addressed with improved locking.
WebKit Bugzilla: 321485
CVE-2026-64779: Shubham Chaskar, Tommy DeVoss from Braze Security Team (@thedawgyg)
Additional recognition
Compression
We would like to acknowledge Tommy DeVoss from Braze Security Team (@thedawgyg) for their assistance.
libcryptex
We would like to acknowledge Ashish Kunwar for their assistance.
WebKit
We would like to acknowledge Henock Habte for their assistance.
macOS Tahoe 26.6.2
Released August 17, 2026
Audio
Available for: macOS Tahoe
Impact: An app may be able to leak sensitive user information
Description: A logic issue was addressed with improved checks.
CVE-2026-65339: Meta Red Team X – Nik Tsytsarkin
ImageIO
Available for: macOS Tahoe
Impact: Processing an image may lead to a denial-of-service
Description: The issue was addressed with improved checks.
CVE-2026-65347: Geonha Lee (@leegn4a)
ImageIO
Available for: macOS Tahoe
Impact: Processing an image may lead to arbitrary code execution
Description: An integer overflow was addressed with improved input validation.
CVE-2026-65346: Meta Red Team X – Nik Tsytsarkin
IOGPUFamily
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
CVE-2026-64788: f00l (@PPPF00L) and 3ndy1(@_3ndy1) and Minghao Lin@Y1nkoc and 云散花折, Arjanit Isufi
Kernel
Available for: macOS Tahoe
Impact: A remote attacker may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory management.
CVE-2026-65343: Drinor Selmanaj (Sentry), Surya Narayan Kushwaha
Kernel
Available for: macOS Tahoe
Impact: An app may be able to cause unexpected system termination or read kernel memory
Description: An out-of-bounds read was addressed with improved input validation.
CVE-2026-65349: an anonymous researcher
Kernel
Available for: macOS Tahoe
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-65330: Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved bounds checking.
WebKit Bugzilla: 317632
CVE-2026-64784: Janggoon Lee of Out of Bounds, OpenAI Codex Security – Amy Burnett
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 313452
CVE-2026-43795: wwwlk
WebKit Bugzilla: 318348
CVE-2026-65338: OpenAI Codex Security – Amy Burnett
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 318405
CVE-2026-65341: Henock Habte
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption vulnerability was addressed with improved locking.
WebKit Bugzilla: 321480
CVE-2026-64782: Seonwook Kim, Shubham Chaskar, lattice, Josef Korbel
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 321484
CVE-2026-64781: Thomas Guillem
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: This issue was addressed through improved state management.
WebKit Bugzilla: 321517
CVE-2026-65351: Niels Hofmans
WebKit Bugzilla: 316996
CVE-2026-65340: Claudio Bozzato and Francesco Benvenuto of Cisco Talos, Josef Korbel (Citadelo)
WebKit Bugzilla: 317142
CVE-2026-65337: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317349
CVE-2026-65336: Josef Korbel
WebKit Bugzilla: 316723
CVE-2026-65335: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317603
CVE-2026-65333: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317450
CVE-2026-65332: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317611
CVE-2026-65331: OpenAI Codex Security – Amy Burnett
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 316347
CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 316918
CVE-2026-64780: OpenAI Codex Security – Amy Burnett
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption issue was addressed with improved state management.
WebKit Bugzilla: 316791
CVE-2026-65334: OpenAI Codex Security – Amy Burnett
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: A memory corruption issue was addressed with improved memory handling.
WebKit Bugzilla: 317317
CVE-2026-43794: Dung Do (@_piers2) of Calif.io
WebKit
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected process termination
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 313703
CVE-2026-64787: 杉山 壮太, Shubham Chaskar
WebKit History
Available for: macOS Tahoe
Impact: Visiting a maliciously crafted website may leak sensitive data
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 315528
CVE-2026-64778: Mohit Negi
WebKit Storage
Available for: macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption vulnerability was addressed with improved locking.
WebKit Bugzilla: 321485
CVE-2026-64779: Shubham Chaskar, Tommy DeVoss from Braze Security Team (@thedawgyg)
Additional recognition
Compression
We would like to acknowledge Tommy DeVoss from Braze Security Team (@thedawgyg) for their assistance.
libcryptex
We would like to acknowledge Ashish Kunwar for their assistance.
WebKit
We would like to acknowledge Henock Habte for their assistance.
Apple also released iOS 18.7.10 and iPadOS 18.7.10 for devices unable to run (or users unwilling to run) iOS 26 and iPadOS 26. Apple did not ship macOS Sequoia or macOS Sonoma updates for Macs unable to run macOS Tahoe.
The updates can be installed by going into the Settings app, then tapping or clicking on “General” section, and then selecting “Software Update.”