Apple released iOS 26.6 and iPadOS 26.6 on July 27, 2026, patching a substantial batch of security vulnerabilities spanning kernel memory corruption, sandbox escapes, and WebKit rendering flaws.
The update applies to iPhone 11 and later, along with a wide range of iPad Pro, Air, and mini models, and addresses issues.
The Kernel component received the heaviest concentration of fixes in this release, with over a dozen distinct entries covering use-after-free conditions, out-of-bounds reads and writes, race conditions, and integer overflows.
Apple iOS 26.6 Fixes Critical Flaws
Several of these flaws could let a malicious app corrupt kernel memory or trigger unexpected system termination, while one entry (CVE-2026-28931) describes a buffer overflow triggered by connecting to a malicious NFS server, potentially leading to kernel memory corruption without requiring a malicious local app.
A standout fix involves AVEVideoEncoder (CVE-2026-64747), where a buffer overflow could allow arbitrary code execution with kernel privileges among the most severe classes of vulnerability, since it grants an attacker the system’s highest level of control.
Two flaws directly address sandbox containment failures. Game Center (CVE-2026-64740) had a path validation issue letting malicious apps break out of their sandbox, while libc (CVE-2026-28973) suffered an integer overflow with the same impact.
Separately, MediaRemote (CVE-2026-43723) contained a path handling flaw that could let an app gain root privileges, effectively bypassing iOS’s privilege separation model entirely.
CloudAttestation (CVE-2026-43813) also stands out: a validation issue could let a maliciously crafted app bypass code signing enforcement, undermining one of iOS’s core anti-malware defenses.
WebKit accounted for a dense cluster of fixes, including multiple use-after-free and memory corruption issues that could crash Safari or leak process memory when rendering malicious web content.
One entry (CVE-2026-64728) addresses an iframe sandboxing policy violation, while another (CVE-2026-43821) fixed an access control flaw letting an app read files outside its sandbox via WebKit.
A privacy-relevant fix (CVE-2026-64713) closes a history-sniffing vector that let websites detect previously visited links.
Apple also patched two curl vulnerabilities (CVE-2026-3784, CVE-2026-3783) tied to authentication credentials leaking cross-origin, plus a libarchive flaw (CVE-2026-4424) risking process memory disclosure, both inherited from upstream open-source dependencies.
Physical-access attackers weren’t ignored either: DriverKit (CVE-2026-43753) and Wi-Fi (CVE-2026-64726) fixes address information leakage and memory corruption achievable by an attacker with proximity or device access.
With dozens of CVEs spanning remote code execution, sandbox bypass, and privilege escalation, iOS 26.6 represents a significant patch cycle.
Security teams managing fleets of iOS/iPadOS devices should prioritize deployment given the kernel-level and code-signing bypass issues, which carry the highest exploitation impact if weaponized in targeted attacks.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.