Apple Fixes 29 Security Flaws: Why iPhone and Mac Users Should Update

Apple Fixes 29 Security Flaws: Why iPhone and Mac Users Should Update

Apple Store in Beijing Sanlitun. Image: Jimmy Jin/Unsplash

Apple fixes 29 security flaws across iOS, iPadOS and macOS, including WebKit and kernel bugs that put users’ data and devices at risk. Update now.

Verfasst von
Aminu Abdullahi
Aminu Abdullahi
Aug 19, 2026

Apple has released security updates fixing up to 29 vulnerabilities across its latest Mac, iPhone and iPad software, including WebKit flaws that could expose sensitive data.

Released Aug. 17, iOS 26.6.1 and iPadOS 26.6.1 address 29 CVEs, while macOS Tahoe 26.6.2 addresses 28. Twenty-one affect WebKit, the browser engine used by Safari. The flaws could trigger browser or process crashes, memory corruption and sensitive data exposure when a device processes specially crafted web content.

The remaining macOS fixes affect Audio, ImageIO, IOGPUFamily and the Kernel. Depending on the flaw, an attacker could cause system crashes, corrupt memory, execute code or access sensitive kernel information. The iPhone update includes those fixes plus a separate Telephony vulnerability that could allow an attacker in a privileged network position to bypass IPSec authentication and intercept network traffic.

Apple also released iOS 18.7.10 and iPadOS 18.7.10 for older iPhones and iPads. Apple’s advisory lists more than 120 CVEs, including more than 40 associated with WebKit.

The updates are available for the iPhone XS, iPhone XS Max, iPhone XR and seventh-generation iPad. The patches address issues that could enable memory corruption, sandbox escapes, kernel memory access and cross-origin data exfiltration.

A faster security cycle

This is Apple’s third security release in three weeks. Some of the fixes had already appeared in beta versions of iOS 27, iPadOS 27 and macOS Golden Gate.

Apple credited Amy Burnett of OpenAI’s Codex Security wholly or jointly with discovering nine of the vulnerabilities.

That could mean more frequent security updates are becoming part of Apple’s normal software cycle rather than an unusual event. For users, however, more patches may mean more interruptions, but delaying them leaves known weaknesses exposed.

Must-read Apple coverage

Advertisement

What users should do

Apple has not identified any of the vulnerabilities as actively exploited, but users should still install the latest security updates promptly. Businesses should prioritize internet-facing, executive, developer and privileged-user devices and verify deployments through their device-management systems.

The key takeaway is that the risk is not limited to Safari: the fixes reach networking, graphics, media and kernel components. Keeping Apple devices current therefore provides broader protection than simply updating a browser.

Read more: For broader context on Apple’s recent patching activity, see the roundup of the company’s major 2026 security events, including zero-days, WebKit vulnerabilities and new background protections.

Aminu Abdullahi

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. He has written for a wide range of technical and business audiences, from IT professionals and cybersecurity leaders to small business owners, executives, and technology buyers. His work has appeared in publications including: TechRepublic eWEEK Channel Insider Geekflare Enterprise Networking Planet eSecurity Planet CIO Insight Webopedia With a background in computer science, Aminu specializes in translating complex technical subjects into clear, practical, and accessible content. His writing helps readers understand emerging technologies, evaluate business software, strengthen cybersecurity strategies, and make more informed decisions about technology investments. Across his work, Aminu focuses on the real-world impact of technology, connecting technical innovation with business value, operational efficiency, security, and long-term digital transformation.