Surprise August patch wave closes nearly thirty iPhone and Mac bugs

Apple's August 17 point releases patch roughly 30 flaws spanning WebKit, the kernel, and IPSec.

AppleThreat Staff
2 Min Read

Apple shipped a surprise stack of point releases on August 17, closing roughly 30 vulnerabilities across iPhone, iPad, and Mac in a single sweep.

iOS 26.6.1 and iPadOS 26.6.1, available for iPhone 11 and later plus a long tail of iPads, fix more than 20 issues. macOS Tahoe 26.6.2 follows with 20 patches of its own. WebKit dominates both advisories, with a long run of memory-corruption bugs that could let malicious web content crash Safari or corrupt memory, several of them reported by OpenAI Codex Security tooling.

Outside the browser, an image-processing integer overflow (CVE-2026-65346) can lead to arbitrary code execution from a single image, while a kernel out-of-bounds read (CVE-2026-65349) lets an app read kernel memory. A use-after-free (CVE-2026-65343) could let a remote attacker crash the system. Researchers at Ruhr University Bochum are credited with CVE-2026-65329, an IPSec authentication bypass that lets an attacker in a privileged network position intercept traffic.

Owners of older hardware get a separate drop: iOS 18.7.10 and iPadOS 18.7.10 cover iPhone XS, XS Max, XR, and the seventh-generation iPad. On the Mac side, build 25G83 also updates Safari to 26.6.2 and the Passwords app to 2.6.2, and carries a firmware update moving Apple silicon mBoot to 18000.161.10. No Sequoia or Sonoma counterparts arrived this time, and the visionOS 26.6.1 advisory is still pending.

Apple has reported no active exploitation of the batch. Users on supported hardware should install the updates from Settings or System Settings without delay.

Share This Article