Breaking
SecurityDeveloping Story

Apple's WebKit Patch Wave Hits 28 Flaws

Apple ships 28-security-fix updates for macOS and iOS, covering two dozen WebKit bugs.

··2 hours ago·2 min read
a laptop computer sitting on top of a white table
Photo by Rahul Chakraborty on Unsplash

Apple's latest round of security updates for its desktop and mobile operating systems closes a broad swath of vulnerabilities, with the majority residing in the company's own WebKit browser engine. The patches, announced Monday, span macOS, iOS, and iPadOS, and arrive as security teams juggle an already active patch cycle.

28 Flaws Across Four Components

macOS Tahoe 26.6.2 leads the release, addressing 28 security defects in total. Of those, 21 sit in WebKit and could result in Safari or process crashes, memory corruption, and sensitive data disclosure, according to Apple's advisory.

The update also resolves seven issues across Audio, ImageIO, IOGPUFamily, and Kernel. Those flaws could enable sensitive user information disclosure, denial-of-service (DoS), arbitrary code execution, memory corruption, system termination, and kernel memory disclosure or corruption.

iOS and iPadOS Get the Same Fixes

iOS 26.6.1 and iPadOS 26.6.1 carry patches for all 28 of those vulnerabilities, along with an authentication issue in Telephony. That Telephony flaw could let an attacker bypass IPSec authentication and intercept network traffic.

The move to ship iOS 26.6.1 and iPadOS 26.6.1 is likely setting the stage for the iOS 27 and iPadOS 27 releases, which are expected to arrive next month, according to the report.

Over 120 Squashed in Older Line

In addition, Apple announced fresh updates for iOS 18.7.10 and iPadOS 18.7.10 that squash over 120 bugs, including more than 40 in WebKit. Those flaws span crashes, memory corruption, and data disclosure, but also include sandbox escape and cross-origin data exfiltration.

The iOS 18.7.10 and iPadOS 18.7.10 updates also resolve 18 vulnerabilities in Kernel. Exploiting those could corrupt kernel memory, crash the system, disclose kernel memory, bypass network filters, write kernel memory, leak sensitive kernel state, and access sensitive user data.

Beyond the Kernel and WebKit

Security defects were also addressed in Accessibility, AirDrop, App Store, AVEVideoEncoder, Contacts, CoreAudio, CoreMedia, Foundation, ImageIO, IOSkywalkFamily, Maps, MediaRemote, Model I/O, SceneKit, Siri, WebRTC, and other components. Apple's advisory does not single out any of these as being exploited in the wild.

Apple's security updates page provides additional details on the individual CVE entries.

Patch Advice Remains Standard

Even though Apple makes no mention of active exploitation, users are advised to apply the patches as soon as possible. The updates are available now for supported devices.

This latest round follows a busy period for Apple-related security. As reported by SecurityWeek, a recent macOS Screen Sharing vulnerability was exploited in attacks. That incident, along with the current WebKit-heavy patch, underscores the importance of staying current with Apple's updates.

Why It Matters

For users, this patch wave is a reminder that the browser engine is a primary attack surface. The inclusion of sandbox escape and cross-origin data exfiltration in the older-line bugs suggests that attackers could potentially break out of the browser's confines, which raises the stakes for patching promptly.

For IT teams, the sheer volume of fixes across both the 26.x and 18.x lines means that any device running an older OS version needs attention. With iOS 27 expected next month, administrators may be tempted to skip the 26.6.1 update, but the WebKit fixes alone justify applying it now.

#apple#webkit#macos#ios#ipados#security-updates

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories