Apple has released the security documentation for iOS 26.6 and iPadOS 26.6, and it is unusually extensive. The list contains 78 documented entries, corresponding to 87 individual CVE numbers. One of the patched vulnerabilities affects a feature that doesn't even exist in the EU.
The update itself arrived on devices on Monday without any major changes: The visible modifications to iOS 26.6 are essentially limited to a rebuilt Spotlight index and a warning message in the Contacts app. The real significance of the release lies in what Apple traditionally publishes only after the release – the list of all vulnerabilities that are addressed with the update. This list is now available and reveals a maintenance update that is anything but minor from a security perspective.
78 entries and 87 CVE numbers
The two numbers differ because multiple entries cover several vulnerabilities at once. A single kernel entry bundles five CVE numbers, while others bundle two. Below the actual list, Apple also includes twelve acknowledgments under the heading "Additional recognition"—these entries acknowledge the contributions of researchers but do not represent Apple's own bug fixes and do not carry their own CVE numbers.
For none of the 78 vulnerabilities does Apple indicate that the vulnerability was actively exploited before being fixed. This distinguishes this update from emergency releases, where the company explicitly notes ongoing exploitation. All fixes apply to iPhone 11 and later, as well as the third and first generation iPad Pro, iPad Air 3, iPad 8, and iPad mini 5 – older models will not receive iOS 26 and therefore none of these fixes.
Which gaps are the most serious?
Several entries stand out from the list, where an attack could reach the deepest system levels. A vulnerability in MediaRemote could have granted an app root privileges, a flaw in AVEVideoEncoder the execution of arbitrary code with kernel privileges. Errors in Game Center and libc allowed a malicious app to escape its sandbox, and a validation problem in CloudAttestation allowed bypassing code signature verification.
On the privacy page, an authorization error in the Contacts app was noted, which allowed an app to create new contacts without consent. Another entry concerning Siri addresses a data breach that allowed an app to access sensitive user data – Apple has completely removed the affected code.
Image files and 3D models make up the largest block
It is striking how heavily the fixes focus on reading media files. Six entries alone are for ImageIO, seven more for Model I/O, and three for SceneKit – a total of 16 locations where, in the worst-case scenario, a specially crafted image, file, or 3D model template could lead to the execution of arbitrary code or the disclosure of process memory. For this attack vector to be effective, it is sufficient that a device is processing a file; conscious opening by the user is not strictly necessary.
The kernel has 14 of its own entries, the potential consequences of which range from writing to and reading from kernel memory and bypassing network filters to unexpected system crashes. WebKit contributes eight entries, plus one each for WebKit Canvas and WebRTC. A Wi-Fi vulnerability completes the picture: An attacker in close physical proximity could have used it to damage process memory.
A patch for a feature that doesn't exist in the EU
The first entry on the entire list concerns accessibility features and describes a case in which an attacker with physical access was able to obtain sensitive data during iPhone synchronization. This feature, known internationally as iPhone Mirroring, mirrors the iPhone screen to a Mac, making it controllable via mouse and keyboard.
In Germany and Austria, you simply can't activate it. Apple has been withholding iPhone Mirroring in the EU since its introduction in 2024, citing regulatory uncertainties surrounding the Digital Markets Act – specifically, concerns that interoperability requirements could force the technology to be opened up to third-party platforms. This remains unchanged even in macOS 27. The patch therefore closes a loophole that is practically irrelevant for EU users and joins the list of Apple features missing in the EU.
The situation is different in Switzerland: As a non-EU and non-EEA country, it is not affected by the DMA block, and iPhone Mirroring is regularly available there. For Swiss users, this entry thus closes a gap in a function that is actually accessible in everyday use.
AI is now on both sides
One detail in the acknowledgments deserves attention. Apple attributes a WebKit vulnerability, which could allow malicious web content to cause a memory error and a Safari crash, to security researchers Milad Nasr and Nicholas Carlini – with the explicit addition that the AI model Claude from Anthropic was involved in the discovery. The same combination appears a second time in the section of additional acknowledgments for WebKit Storage.
This marks the first time that machine-assisted vulnerability scanning has been prominently featured in Apple's own security documentation. At the end of June, the company had prioritized a number of fixes, citing the risk posed by AI-powered attack tools. The current list demonstrates the opposite direction of this same development: the same technology that accelerates the discovery of vulnerabilities for attackers also accelerates it for defenses.
Apple's security pace is increasing
The update was released simultaneously for iPadOS 26.6 and the corresponding versions of macOS Tahoe, watchOS, tvOS, and visionOS. On iPhones, the update can be installed under Settings → General → Software Update.
With 78 entries, this release is significantly more extensive than what Apple typically handles in a regular interim update and follows only about four weeks after the unscheduled security update to 26.5.2. Two major security releases within a month are unusually close for an ongoing version cycle. Distribution is handled via the same mechanism Apple uses to deliver security updates for older system versions – users who have disabled automatic installation must initiate the download manually. (Image: Apfelpatient)
- Amazon plans 5,105 satellites for iPhone features
- iOS 26.6 is here: These are the new features the update brings
- Silo Season 4 starts in summer 2027
- Neuromancer on Apple TV: Teaser and release date confirmed
- AppleCare One launches in Germany: Prices, scope & limitations
- Apple vs. Micron: Dispute over Chinese storage ends up with Trump
- Trump threatens the EU with tariffs over tech fines
- Claude Opus 5: Anthropic's new AI model is here



