Apple closed out July with a security update cycle of unprecedented scale, releasing iOS 26.6 and macOS Tahoe 26.6 alongside patches for iPadOS, watchOS, tvOS, and visionOS. The combined count across all platforms reaches 194 unique CVE identifiers, making this the company’s largest coordinated fix dispatch in a single day.
The core iPhone and iPad release contains 87 CVEs drawn from 78 individual advisory entries. Apple’s macOS Tahoe 26.6 security documentation lists 155 CVEs, a figure that includes both shared fixes and Mac-only patches addressing Gatekeeper evasion, sandbox weaknesses, and privilege escalation. Users on older Mac operating systems receive equivalent protection through macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8, both published the same day.
Researchers found multiple bugs that security-conscious users should treat as urgent. A MediaRemote flaw handed root access to any app that reached it. An AVEVideoEncoder bug offered kernel-level code execution. Game Center and libc each had sandbox escape vulnerabilities. CloudAttestation contained a hole allowing malicious applications to bypass Apple’s code-signing enforcement. Three separate SceneKit issues and an ImageIO flaw all created pathways for arbitrary code execution through crafted image and media content.
Kernel-level patches address memory corruption, privilege escalation, and network filter circumvention. WebKit receives fixes blocking cross-tab memory leakage, link-visit fingerprinting, UI spoofing, and iframe sandbox violations. A Wi-Fi driver vulnerability allows attackers in close proximity to trigger memory corruption through malformed wireless frames.
Apple stated that it has no knowledge of active exploitation for any of the vulnerabilities fixed in this batch. The company encourages all users to update through the Settings app on mobile devices and System Settings on Mac.