Safari 26.6.1 Patches 21 WebKit Flaws, Screen Sharing Zero-Day Already Exploited

Apple released macOS Sonoma 14.8.9, macOS Sequoia 15.7.9, and macOS Tahoe 26.6.1 on August 6, 2026, addressing 29 CVEs with particular urgency around a Screen Sharing authentication flaw that the Netherlands’ National Cyber Security Center (NCSC-NL) confirmed is already being exploited in active attacks.

The update arrived just over a week after macOS Tahoe 26.6 and skipped developer and public beta phases entirely. This suggests Apple’s shift toward emergency security releases when zero-day exploitation is confirmed. Of the 29 vulnerabilities patched, 21 are WebKit-related, meaning Safari’s rendering engine remains the primary attack surface across iOS and macOS.

Safari

The most urgent fix addresses an authentication bypass in macOS Screen Sharing that allowed attackers to gain access without valid credentials. NCSC-NL’s confirmation that this vulnerability is being actively exploited in the wild elevates the priority for any macOS user who relies on Screen Sharing for remote access.

The theoretical risk, the flaw has moved from discovered to weaponized, meaning exploitation toolkits likely exist or will exist within days. Mac users running Sonoma, Sequoia, or earlier versions of Tahoe should treat this update as mandatory.

Of the 29 CVEs, 21 target WebKit flaws, the engine powering Safari on macOS and all web rendering on iOS. This concentration shows a persistent fact: Safari’s renderer is the most frequently attacked component of Apple’s platforms.

  • CVE-2026-64728: Use-after-free in WebKit causing unexpected Safari crashes when processing maliciously crafted web content.
  • CVE-2026-64783: Memory corruption in WebKit affecting macOS Sonoma and Sequoia, credited to 杉山 壮太, lattice, Behzad Najjarpour Jabbari, and Junyeong Lee.
  • CVE-2026-43740: Privacy leak allowing websites to determine if a user had visited a specific link, fixed by Arni Hardarson and Nathaniel Oh.
  • CVE-2026-64713: UI spoofing vulnerability allowing malicious framed content to deceive users about which site they are viewing, found by Kwak Kiyong and Song Nuri.

Beyond the WebKit fixes, Apple patched an audio vulnerability capable of leaking sensitive user information, an image processing flaw that could enable arbitrary code execution, and three separate kernel vulnerabilities.

9 of the 29 CVEs are credited to OpenAI Codex Security, Apple’s AI-assisted vulnerability detection tool. This marks a significant shift in Apple’s security research pipeline toward automated, machine-learning-powered detection of flaws that human reviewers might miss. Apple has not publicly disclosed how many vulnerabilities the tool has identified across all 2026 releases.

For older hardware unable to run iOS 26 or iPadOS 26, Apple released iOS 18.7.10 and iPadOS 18.7.10 with select security patches, though the older versions do not receive the full patch set. Devices on iOS 18 remain vulnerable to flaws that users on iOS 26 have patched, a gap that widens as exploits become publicly known.

Newsletter
Never miss an Apple story
One email a day, the news that matters. No spam, unsubscribe anytime.
About the Author

Imran Hussain is the founder and editor of iThinkDifferent, which he launched in 2008 to cover Apple news, reviews, and how-to guides. He has spent over 15 years writing about iOS, macOS, and the wider Apple ecosystem, with a focus on hands-on guides - installing developer betas, troubleshooting, and walking through new features on his own devices. Based in Dubai, he also loves to cover photography, gaming, and the tech industry more broadly on his social media profiles.

Leave a Reply