Following the release of iOS 26.6, iPadOS 26.6, and related software updates, Apple has detailed a huge number of security fixes included in today’s new OS versions.
Across iOS 26.6 and iPadOS 26.6, Apple details more than 75 security fixes for iPhone and iPad. These fixes cover a broad range of parts of the system.
More precisely, Apple’s advisory contains 78 individual vulnerability entries tied to 87 unique CVE numbers. The CVE count is higher because several entries address more than one CVE.
Apple does not say that any of the vulnerabilities fixed in iOS 26.6 were actively exploited in the wild.
Several of the fixes stand out among Apple’s lengthy list:
A MediaRemote flaw could let an app gain root privileges.
An AVEVideoEncoder vulnerability could let an app execute arbitrary code with kernel privileges.
Vulnerabilities in Game Center and libc could let a malicious app escape its sandbox.
A CloudAttestation flaw could let a malicious app bypass code-signing enforcement.
An ImageIO vulnerability could lead to arbitrary code execution when processing a maliciously crafted image.
... continue reading