iOS 26.6 Fixes 87 Security Vulnerabilities Across Kernel, WebKit, and More

Apple has released iOS 26.6 and iPadOS 26.6 with a security patch larger than it first appears: the advisory contains 78 individual vulnerability entries tied to 87 unique CVE numbers, with the higher CVE count because several entries cover more than one flaw. Apple says none of the vulnerabilities were actively exploited in the wild before this release, but the scope of what is fixed here makes a strong case for updating sooner rather than later.

The breadth is significant as the fixes span kernel, WebKit, sandbox boundaries, code-signing enforcement, image parsing, and more. This comes about a month after iOS 26.5.2, which Apple accelerated due to concerns about AI-assisted hacking tools reducing the safe window between patch disclosure and exploitation.

iOS 26.6

The vulnerabilities that matter most

Several fixes address high-severity issues that could give an attacker significant control over a device. A MediaRemote flaw could let an app gain root privileges, and an AVEVideoEncoder vulnerability could let an app execute arbitrary code with kernel privileges. Sandbox escapes in Game Center and libc are also patched, along with a CloudAttestation flaw that could let a malicious app bypass code-signing enforcement.

Kernel and WebKit each received particular attention:

  • Kernel: More than a dozen vulnerabilities fixed, with potential impacts including corrupting or writing to kernel memory, disclosing kernel memory, bypassing network filters, and causing unexpected system termination.
  • WebKit: Multiple fixes covering process memory exposure, link-visit history disclosure, interface spoofing, iframe sandbox violations, out-of-sandbox file reads, and Safari crashes.
  • ImageIO: A vulnerability that could lead to arbitrary code execution when processing a maliciously crafted image.
  • SceneKit: Three separate vulnerabilities that could lead to arbitrary code execution when processing maliciously crafted files.

The ImageIO and SceneKit issues deserve attention because they are file-parsing bugs, the kind that can be triggered without meaningful user interaction beyond opening a file or loading a webpage.

Apple says no vulnerabilities in this release were actively exploited before today, but the kernel and WebKit fixes are the type that tend to attract attention once they are publicly disclosed. The combination of 87 CVEs and zero active exploits is a reasonable window to update on your own schedule, though that window tends to close quickly after a release like this.

iOS 26.6 is available now via Settings > General > Software Update on all compatible iPhones. It is almost certainly the last significant update iOS 26 will receive before iOS 27 ships, so it is worth treating as the final maintenance pass on a mature OS rather than a routine point release you can defer indefinitely. For a look at what is waiting on the other side of that upgrade, the iOS 27 performance improvements are worth reviewing before you make the jump.

About the Author

Imran Hussain is the founder and editor of iThinkDifferent, which he launched in 2008 to cover Apple news, reviews, and how-to guides. He has spent over 15 years writing about iOS, macOS, and the wider Apple ecosystem, with a focus on hands-on guides - installing developer betas, troubleshooting, and walking through new features on his own devices. Based in Dubai, he also loves to cover photography, gaming, and the tech industry more broadly on his social media profiles.

Leave a comment