Apple has patched vulnerabilities that could give attackers root access, execute malicious code or expose protected data across iPhones, Macs and several other devices.
The company released iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, watchOS 26.6, tvOS 26.6 and visionOS 26.6 as part of a security rollout covering 194 unique vulnerabilities after overlapping fixes are removed. Apple said it is not aware of the iPhone and iPad flaws being exploited in attacks.
The fixes cover a wide range of system components, including the kernel, WebKit, Wi-Fi, ImageIO, SceneKit, Game Center, Contacts and MediaRemote. Several vulnerabilities could have allowed malicious apps to gain elevated privileges, execute code with kernel access, escape app sandbox protections or bypass security checks.
Serious flaws fixed across Apple devices
Some of the more notable iPhone and iPad fixes include a MediaRemote flaw that could allow an app to gain root privileges and an AVEVideoEncoder vulnerability that could enable arbitrary code execution with kernel privileges. Apple also patched issues involving ImageIO and SceneKit that could allow attackers to run malicious code when users opened specially crafted images or files.
The company also addressed kernel vulnerabilities that could expose sensitive memory, corrupt system memory, bypass network protections or cause unexpected crashes. WebKit, the engine behind Safari, received multiple fixes for issues that could expose browsing information, bypass sandbox protections or allow malicious content to access restricted areas.
A separate Wi-Fi vulnerability was also patched. The flaw could have allowed a nearby attacker to corrupt process memory, creating another potential attack path for users in vulnerable environments.
Mac receives even larger security update
Mac users received an even bigger batch of fixes. Apple’s macOS Tahoe 26.6 security notes list 155 unique CVEs, addressing problems that could allow apps to gain root access, bypass Gatekeeper protections, escape sandbox restrictions or access protected user data.
Apple also released security updates for older macOS versions, although those fixes are counted separately from the 155 vulnerabilities listed for macOS Tahoe 26.6.
Updates were also released for watchOS 26.6, tvOS 26.6 and visionOS 26.6. After removing overlapping fixes across platforms, Apple’s latest software releases address 194 unique vulnerabilities across its operating systems.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
Why this update matters
The scale of this release underscores how quickly software security risks continue to grow. While Apple has not reported active exploitation of these vulnerabilities, many of the patched issues involve high-impact areas such as system privileges, browser security and access to protected data.
For consumers, the risk is not limited to downloading suspicious apps. A vulnerable component like WebKit or image processing software can become a security problem simply through visiting a malicious website or opening a crafted file.
The challenge for Apple and other software makers is balancing rapid security fixes with keeping devices stable. Large updates can sometimes introduce compatibility issues or require significant download time, but delaying security patches leaves devices exposed for longer.
Read more: Apple recently patched a year-old Hide My Email bug that exposed privacy concerns.