Apple’s iOS 26.6 update addresses a substantial number of security flaws — 78 documented vulnerability entries tied to 87 unique CVE identifiers for iPhone and iPad alone. While the update may appear minor on the surface, with only a handful of new features, the security bulletin tells a different story. Across all Apple platforms, including macOS Tahoe 26.6, watchOS 26.6, tvOS 26.6, and visionOS 26.6, the company patched 194 unique vulnerabilities in a single release cycle. Apple has not reported evidence that any of these flaws were actively exploited in the wild — but the sheer volume and severity of the fixes make prompt installation advisable.

What you need to know

  • iOS 26.6 and iPadOS 26.6 contain 78 security entries covering 87 unique CVE identifiers, according to Apple’s official security bulletin.
  • Critical flaws include a MediaRemote bug granting root access, a kernel-level code execution vulnerability in AVEVideoEncoder, and sandbox escapes in Game Center and libc.
  • Across all platforms (iOS, iPadOS, macOS, watchOS, tvOS, visionOS), Apple closed 194 unique vulnerabilities in this release.
  • Apple has not confirmed any of these vulnerabilities were exploited in real-world attacks, but publication of the details itself increases risk for unpatched devices.
The iOS 26.6 update is now available, though many users are unsure whether to install it immediately.
The update is now available, though many users are unsure whether to install it immediately.

Key iPhone vulnerabilities patched in iOS 26.6

The fixes span a wide range of system components, from image processing to the Contacts app. According to Apple’s security bulletin, the 78 entries and 87 CVE numbers don’t match one-to-one because some entries address multiple CVEs simultaneously. Among the most notable flaws:

  • A MediaRemote bug allowed an app to gain root (superuser) privileges.
  • An AVEVideoEncoder vulnerability enabled arbitrary code execution with kernel-level privileges.
  • Flaws in Game Center and libc allowed malicious apps to escape the sandbox.
  • A CloudAttestation issue bypassed code signature verification.
  • An ImageIO vulnerability could trigger code execution simply by opening a specially crafted image.
  • Three SceneKit vulnerabilities risked code execution when processing malicious files.
  • An Accessibility bug could expose personal data via iPhone Mirroring to someone with physical access to the device.
  • A Contacts bug allowed an app to add contacts without the owner’s permission.
Numerous security issues were fixed across the system in iOS 26.6.
Numerous security issues were fixed across the system.

Critical WebKit and kernel vulnerabilities

Apple separately patched more than a dozen kernel vulnerabilities. The potential consequences of these flaws included kernel memory corruption or unauthorized writes, leaking kernel memory contents, bypassing network filters, and unexpected device reboots during use.

The WebKit engine — which powers Safari and nearly all web content rendering on iPhone — also received a significant set of fixes. The vulnerabilities could have allowed attackers to leak process memory, determine whether a user had visited a specific link, spoof the user interface, violate iframe isolation rules, read files outside the sandbox, or crash the browser entirely.

An additional wireless vulnerability is also noteworthy: according to the source, a nearby attacker could corrupt process memory via Wi-Fi. Beyond the 78 documented fixes, Apple included a separate acknowledgments section crediting 12 security researchers, though these entries do not have their own CVE numbers and are not counted as separate fixes.

Vulnerabilities were also found in Safari's WebKit engine.
Vulnerabilities were also found in Safari’s WebKit engine.

Which Apple devices received security updates

The security fixes extend well beyond iPhone and iPad. The macOS Tahoe 26.6 security notes list 155 unique CVEs. In addition to fixes shared with the mobile platforms, the Mac update closes vulnerabilities that could allow apps to gain root access, escape the sandbox, bypass Gatekeeper checks and privacy settings, or access protected data.

Apple also released updates for watchOS 26.6, tvOS 26.6, and visionOS 26.6. Older macOS versions received their own security updates as well, though those were not included in the overall count. After removing overlapping CVEs across platforms, the source reports that Apple closed 194 unique vulnerabilities in a single day — a large number even by the standards of major releases.

The update was released not only for iPhone but also for other Apple devices.
The update was released not only for iPhone but also for other Apple devices.

Why prompt installation matters

Even though Apple has not confirmed active exploitation of any of these vulnerabilities, the publication of the vulnerability list itself serves as a roadmap for attackers. Once fixes are publicly documented, threat actors can reverse-engineer the patches to target devices that have not yet been updated.

The source also notes that Apple had previously indicated it accelerated the release of some fixes in the prior iOS 26.5.2 update due to AI-based exploitation tools, suggesting that attacks are becoming faster and patches need to arrive ahead of them.

To install the update, navigate to Settings → General → Software Update on your iPhone or iPad. The full list of fixes and researcher acknowledgments is available on Apple’s official security support page.

Updating to iOS 26.6 is recommended without delay.
Updating to iOS 26.6 is recommended without delay.