Apple Pushes Fixes for Hundreds of Security Flaws Across iPhones, Macs, and More

The latest software updates cover 87 flaws in iOS and 155 in macOS Tahoe, including one that lets a remote attacker corrupt the core of the operating system.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A digital montage of AI technology identifying vulnerabilities in software code
Share

Key points

  • Apple released patches on Monday addressing 87 vulnerabilities in iOS 26 and iPadOS 26.
  • MacOS Tahoe 26.6 received the largest single-platform fix count: 155 vulnerabilities.
  • One flaw, CVE-2026-43810, allows a remote attacker to corrupt kernel memory, the deepest, most privileged layer of the operating system.
  • WatchOS, tvOS, and visionOS each received patches for roughly 100 vulnerabilities.
  • Apple's advisories confirm none of the flaws are known to be actively exploited right now.

Apple has shipped software updates covering hundreds of security vulnerabilities across every major platform it makes: iPhones, iPads, Macs, Apple Watches, Vision Pro headsets, and Apple TVs.

The patches arrived Monday with no prior warning, which is standard Apple practice.

How bad are these flaws?

None are confirmed as actively exploited in the wild. Genuinely reassuring, but the variety of what they could allow if left unpatched is worth understanding.

Across iOS 26 and iPadOS 26, Apple fixed 87 vulnerabilities. Possible consequences include apps reading private data they should never see, attackers running arbitrary code on your device, and an intruder adding contacts or spoofing the screen interface without your permission.

MacOS Tahoe 26.6 topped the list with 155 fixes. Two older Mac operating systems also got updates: macOS Sequoia 15.7.8 with 138 fixes, and macOS Sonoma 14.8.8 with 127.

Platform Update version Vulnerabilities fixed
iOS and iPadOS 26.6 87
macOS Tahoe 26.6 155
macOS Sequoia 15.7.8 138
macOS Sonoma 14.8.8 127
watchOS / tvOS / visionOS various ~100 each
Safari latest ~12

Which flaw deserves the closest attention?

One stands out. CVE-2026-43810 lets a remote user, someone without physical access to your device, corrupt kernel memory. The kernel is the innermost part of the operating system; it controls everything else. Corrupting it can give an attacker total control.

We first flagged this CVE on 28 July 2026. Adam Boynton, senior enterprise strategy manager at device-management firm Jamf, told SecurityWeek: "remote changes the economics of an attack chain considerably." A flaw that needs physical access is hard to exploit at scale. One that works over a network isn't.

Safari also received roughly a dozen fixes, including flaws that could expose private user data or crash the browser.

What should iPhone and Mac users actually do?

Update now. On an iPhone or iPad, go to Settings, then General, then Software Update. On a Mac, open System Settings, then General, then Software Update.

If you're running Sequoia or Sonoma rather than Tahoe, updates are still available. Apple patched all three macOS generations. Don't assume older hardware means you're left behind.

Watch and TV users should check their device settings too. Fix counts there are just as large.

No evidence exists that criminals are actively using any of these flaws today. Applying the update before that changes costs five minutes. Waiting costs considerably more if the calculation shifts.

© 2026 Threat Vectr