Apple's WebKit Patch Wave Hits 28 Flaws
Apple ships 28-security-fix updates for macOS and iOS, covering two dozen WebKit bugs.
Apple's latest round of security updates for its desktop and mobile operating systems closes a broad swath of vulnerabilities, with the majority residing in the company's own WebKit browser engine. The patches, announced Monday, span macOS, iOS, and iPadOS, and arrive as security teams juggle an already active patch cycle.
28 Flaws Across Four Components
macOS Tahoe 26.6.2 leads the release, addressing 28 security defects in total. Of those, 21 sit in WebKit and could result in Safari or process crashes, memory corruption, and sensitive data disclosure, according to Apple's advisory.
The update also resolves seven issues across Audio, ImageIO, IOGPUFamily, and Kernel. Those flaws could enable sensitive user information disclosure, denial-of-service (DoS), arbitrary code execution, memory corruption, system termination, and kernel memory disclosure or corruption.
iOS and iPadOS Get the Same Fixes
iOS 26.6.1 and iPadOS 26.6.1 carry patches for all 28 of those vulnerabilities, along with an authentication issue in Telephony. That Telephony flaw could let an attacker bypass IPSec authentication and intercept network traffic.
The move to ship iOS 26.6.1 and iPadOS 26.6.1 is likely setting the stage for the iOS 27 and iPadOS 27 releases, which are expected to arrive next month, according to the report.
Over 120 Squashed in Older Line
In addition, Apple announced fresh updates for iOS 18.7.10 and iPadOS 18.7.10 that squash over 120 bugs, including more than 40 in WebKit. Those flaws span crashes, memory corruption, and data disclosure, but also include sandbox escape and cross-origin data exfiltration.
The iOS 18.7.10 and iPadOS 18.7.10 updates also resolve 18 vulnerabilities in Kernel. Exploiting those could corrupt kernel memory, crash the system, disclose kernel memory, bypass network filters, write kernel memory, leak sensitive kernel state, and access sensitive user data.
Beyond the Kernel and WebKit
Security defects were also addressed in Accessibility, AirDrop, App Store, AVEVideoEncoder, Contacts, CoreAudio, CoreMedia, Foundation, ImageIO, IOSkywalkFamily, Maps, MediaRemote, Model I/O, SceneKit, Siri, WebRTC, and other components. Apple's advisory does not single out any of these as being exploited in the wild.
Apple's security updates page provides additional details on the individual CVE entries.
Patch Advice Remains Standard
Even though Apple makes no mention of active exploitation, users are advised to apply the patches as soon as possible. The updates are available now for supported devices.
This latest round follows a busy period for Apple-related security. As reported by SecurityWeek, a recent macOS Screen Sharing vulnerability was exploited in attacks. That incident, along with the current WebKit-heavy patch, underscores the importance of staying current with Apple's updates.
Why It Matters
For users, this patch wave is a reminder that the browser engine is a primary attack surface. The inclusion of sandbox escape and cross-origin data exfiltration in the older-line bugs suggests that attackers could potentially break out of the browser's confines, which raises the stakes for patching promptly.
For IT teams, the sheer volume of fixes across both the 26.x and 18.x lines means that any device running an older OS version needs attention. With iOS 27 expected next month, administrators may be tempted to skip the 26.6.1 update, but the WebKit fixes alone justify applying it now.
Sources
- SecurityWeek Original source
- security updates Also reporting
- Recent macOS Screen Sharing Vulnerability Exploited in Attacks Also reporting
Continue Reading
AI Labs Compete Over Rogue Agent Claims
Anthropic and OpenAI trade narratives of accidental sandbox escapes, raising questions about the safety of their frontier models.
CAF Bank Stalls on Online Restoration
Thousands of UK charities face payroll delays as CAF Bank remains offline a week after detecting a third-party security flaw.
GitLab Critical Flaw Allows Unauthenticated Project Deletion
A critical GitLab vulnerability could let unauthenticated attackers modify or delete public projects and user data.