Dozens of WebKit vulnerabilities fixed with new macOS, iOS security updates

Apple on Monday announced a new round of macOS, iOS and iPadOS security updates that address dozens of vulnerabilities, most of which affect the WebKit web browser engine.

macOS Tahoe 26.6.2 is now distributed with fixes for 28 security flaws, including 21 in WebKit, that could cause Safari/process crashes, memory corruption, and sensitive data exposure.

The update also resolves seven issues in Audio, ImageIO, IOGPUFamily, and Kernel that could lead to disclosure of sensitive user information, denial of service (DoS), arbitrary code execution, memory corruption, system crash, and kernel memory disclosure or corruption.

iOS 26.6.1 and iPadOS 26.6.1 were released with patches for all 28 of these vulnerabilities, as well as fixes for an authentication issue in telephony that could allow attackers to bypass IPSec authentication and intercept network traffic.

The fresh iOS 26.6.1 and iPadOS 26.6.1 updates likely herald the iOS 27 and iPadOS 27 releases expected to arrive next month.

On Monday, Apple also announced new updates for iOS 18.7.10 and iPadOS 18.7.10 that fix more than 120 bugs, including more than 40 in WebKit.

Advertising. Scroll to continue reading.

In addition to crashes, memory corruption, and data disclosure, these flaws can also lead to evasion of test environments and extraction of data from disparate sources.

The update also resolves 18 kernel vulnerabilities that can be exploited to corrupt kernel memory, crash the system, expose kernel memory, bypass network filters, write kernel memory, leak sensitive kernel state, and access sensitive user data.

Security flaws were also addressed in Accessibility, AirDrop, App Store, AVEVideoEncoder, Contacts, CoreAudio, CoreMedia, Foundation, ImageIO, IOSkywalkFamily, Maps, MediaRemote, Model I/O, SceneKit, Siri, WebRTC, and other components.

Apple does not mention any of these vulnerabilities being exploited in the wild, but users are advised to apply the patches as soon as possible. Additional information can be found at Apple security updates page.

Related: Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Related: Critical SAP Commerce Cloud vulnerability exploited 3 days after disclosure

Related: Hackers exploit unpatched GeoServer Zero-Day

Related: An Adobe Commerce bug was addressed immediately upon discovery

Leave a Reply

Your email address will not be published. Required fields are marked *