Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
Apple released security updates for macOS Tahoe 26.6.2, iOS 26.6.1, and iPadOS 26.6.1 addressing 28 vulnerabilities, with 21 in WebKit alone iOS 18.7.10 and iPadOS 18.7.10 updates patch over 120 bugs, including 40+ WebKit flaws and 18 Kernel vulnerabilities WebKit remains the most heavily affected component across all updates, with flaws enabling crashes, memory corruption, sandbox escapes, and cross-origin data exfiltration A critical Telephony authentication issue in iOS/iPadOS 26.6.1 allows I
Analysis
TL;DR
- Apple released security updates for macOS Tahoe 26.6.2, iOS 26.6.1, and iPadOS 26.6.1 addressing 28 vulnerabilities, with 21 in WebKit alone
- iOS 18.7.10 and iPadOS 18.7.10 updates patch over 120 bugs, including 40+ WebKit flaws and 18 Kernel vulnerabilities
- WebKit remains the most heavily affected component across all updates, with flaws enabling crashes, memory corruption, sandbox escapes, and cross-origin data exfiltration
- A critical Telephony authentication issue in iOS/iPadOS 26.6.1 allows IPSec authentication bypass and network traffic interception
- Apple confirmed no active exploitation in the wild but urges immediate patching
Why It Matters
This represents one of the largest single security update cycles in recent Apple history, with over 148 total vulnerabilities patched across multiple OS versions. The heavy concentration of WebKit flaws underscores the browser engine's continued role as the primary attack surface for iOS and macOS, making these patches critical for enterprise and consumer security postures ahead of the iOS 27 release.
Technical Details
- macOS Tahoe 26.6.2: 28 security defects fixed — 21 in WebKit (crashes, memory corruption, data disclosure), 7 in Audio, ImageIO, IOGPUFamily, and Kernel (DoS, arbitrary code execution, kernel memory corruption)
- iOS 26.6.1 / iPadOS 26.6.1: Patches all 28 vulnerabilities from the macOS update plus a Telephony IPSec authentication bypass that could enable network traffic interception
- iOS 18.7.10 / iPadOS 18.7.10: Over 120 bug fixes including 40+ WebKit vulnerabilities (sandbox escape, cross-origin exfiltration) and 18 Kernel flaws (kernel memory corruption, network filter bypass, sensitive data access)
- Additional affected components: Accessibility, AirDrop, App Store, AVEVideoEncoder, Contacts, CoreAudio, CoreMedia, Foundation, ImageIO, IOSkywalkFamily, Maps, MediaRemote, Model I/O, SceneKit, Siri, and WebRTC
- No known active exploitation reported by Apple for any of the patched vulnerabilities
Industry Insight
- The sheer volume of WebKit vulnerabilities across multiple branches signals that browser engine hardening should remain a top priority for Apple and enterprise security teams alike
- The IPSec authentication bypass in Telephony is particularly concerning for enterprise environments relying on secure VPN connections — organizations should verify patch deployment across all iOS/iPadOS devices immediately
- With iOS 27 expected next month, these updates serve as both a cleanup cycle and a stability foundation, suggesting that any remaining unpatched issues may be addressed in the major release rather than waiting for additional point updates
Disclaimer: The above content is generated by AI and is for reference only.