apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result

iOS 26.6 closes 78 security vulnerabilities on iPhone and iPad

by Milan
July 27, 2026 - 8:46 PM
in Apple News
iOS 26.6 Apple security vulnerabilities

Image: Apfelpatient

Apple has released the security documentation for iOS 26.6 and iPadOS 26.6, and it is unusually extensive. The list contains 78 documented entries, corresponding to 87 individual CVE numbers. One of the patched vulnerabilities affects a feature that doesn't even exist in the EU.

The update itself arrived on devices on Monday without any major changes: The visible modifications to iOS 26.6 are essentially limited to a rebuilt Spotlight index and a warning message in the Contacts app. The real significance of the release lies in what Apple traditionally publishes only after the release – the list of all vulnerabilities that are addressed with the update. This list is now available and reveals a maintenance update that is anything but minor from a security perspective.

78 entries and 87 CVE numbers

The two numbers differ because multiple entries cover several vulnerabilities at once. A single kernel entry bundles five CVE numbers, while others bundle two. Below the actual list, Apple also includes twelve acknowledgments under the heading "Additional recognition"—these entries acknowledge the contributions of researchers but do not represent Apple's own bug fixes and do not carry their own CVE numbers.

For none of the 78 vulnerabilities does Apple indicate that the vulnerability was actively exploited before being fixed. This distinguishes this update from emergency releases, where the company explicitly notes ongoing exploitation. All fixes apply to iPhone 11 and later, as well as the third and first generation iPad Pro, iPad Air 3, iPad 8, and iPad mini 5 – older models will not receive iOS 26 and therefore none of these fixes.

Which gaps are the most serious?

Several entries stand out from the list, where an attack could reach the deepest system levels. A vulnerability in MediaRemote could have granted an app root privileges, a flaw in AVEVideoEncoder the execution of arbitrary code with kernel privileges. Errors in Game Center and libc allowed a malicious app to escape its sandbox, and a validation problem in CloudAttestation allowed bypassing code signature verification.

On the privacy page, an authorization error in the Contacts app was noted, which allowed an app to create new contacts without consent. Another entry concerning Siri addresses a data breach that allowed an app to access sensitive user data – Apple has completely removed the affected code.

Image files and 3D models make up the largest block

It is striking how heavily the fixes focus on reading media files. Six entries alone are for ImageIO, seven more for Model I/O, and three for SceneKit – a total of 16 locations where, in the worst-case scenario, a specially crafted image, file, or 3D model template could lead to the execution of arbitrary code or the disclosure of process memory. For this attack vector to be effective, it is sufficient that a device is processing a file; conscious opening by the user is not strictly necessary.

The kernel has 14 of its own entries, the potential consequences of which range from writing to and reading from kernel memory and bypassing network filters to unexpected system crashes. WebKit contributes eight entries, plus one each for WebKit Canvas and WebRTC. A Wi-Fi vulnerability completes the picture: An attacker in close physical proximity could have used it to damage process memory.

A patch for a feature that doesn't exist in the EU

The first entry on the entire list concerns accessibility features and describes a case in which an attacker with physical access was able to obtain sensitive data during iPhone synchronization. This feature, known internationally as iPhone Mirroring, mirrors the iPhone screen to a Mac, making it controllable via mouse and keyboard.

In Germany and Austria, you simply can't activate it. Apple has been withholding iPhone Mirroring in the EU since its introduction in 2024, citing regulatory uncertainties surrounding the Digital Markets Act – specifically, concerns that interoperability requirements could force the technology to be opened up to third-party platforms. This remains unchanged even in macOS 27. The patch therefore closes a loophole that is practically irrelevant for EU users and joins the list of Apple features missing in the EU.

The situation is different in Switzerland: As a non-EU and non-EEA country, it is not affected by the DMA block, and iPhone Mirroring is regularly available there. For Swiss users, this entry thus closes a gap in a function that is actually accessible in everyday use.

AI is now on both sides

One detail in the acknowledgments deserves attention. Apple attributes a WebKit vulnerability, which could allow malicious web content to cause a memory error and a Safari crash, to security researchers Milad Nasr and Nicholas Carlini – with the explicit addition that the AI model Claude from Anthropic was involved in the discovery. The same combination appears a second time in the section of additional acknowledgments for WebKit Storage.

This marks the first time that machine-assisted vulnerability scanning has been prominently featured in Apple's own security documentation. At the end of June, the company had prioritized a number of fixes, citing the risk posed by AI-powered attack tools. The current list demonstrates the opposite direction of this same development: the same technology that accelerates the discovery of vulnerabilities for attackers also accelerates it for defenses.

Apple's security pace is increasing

The update was released simultaneously for iPadOS 26.6 and the corresponding versions of macOS Tahoe, watchOS, tvOS, and visionOS. On iPhones, the update can be installed under Settings → General → Software Update.

With 78 entries, this release is significantly more extensive than what Apple typically handles in a regular interim update and follows only about four weeks after the unscheduled security update to 26.5.2. Two major security releases within a month are unusually close for an ongoing version cycle. Distribution is handled via the same mechanism Apple uses to deliver security updates for older system versions – users who have disabled automatic installation must initiate the download manually. (Image: Apfelpatient)

  • Amazon plans 5,105 satellites for iPhone features
  • iOS 26.6 is here: These are the new features the update brings
  • Silo Season 4 starts in summer 2027
  • Neuromancer on Apple TV: Teaser and release date confirmed
  • AppleCare One launches in Germany: Prices, scope & limitations
  • Apple vs. Micron: Dispute over Chinese storage ends up with Trump
  • Trump threatens the EU with tariffs over tech fines
  • Claude Opus 5: Anthropic's new AI model is here
Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Tags: iOSiOS 26.6iPadOSiPadOS 26.6macOSmacOS 26.6

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Previous Post

iPhone and Satellite Features: These Countries Are Included

iOS 26.6 closes 78 security vulnerabilities on iPhone and iPad">
iOS 26.6 Apple security vulnerabilities

iOS 26.6 closes 78 security vulnerabilities on iPhone and iPad

July 27, 2026
iPhone Apple Satellite Features

iPhone and Satellite Features: These Countries Are Included

July 27, 2026
Amazon Satellite iPhone

Amazon plans 5,105 satellites for iPhone features

July 27, 2026

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube threads threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch