Apple Pushes Fixes for Hundreds of Security Flaws Across iPhones, Macs, and More

The latest software updates cover 87 flaws in iOS and 155 in macOS Tahoe, including one that lets a remote attacker corrupt the core of the operating system.

ThreatVectr Newsdesk· 3 min read
A digital montage of AI technology identifying vulnerabilities in software code
Share

Key points

  • Apple released patches on Monday addressing 87 vulnerabilities in iOS 26 and iPadOS 26.
  • macOS Tahoe 26.6 received the largest single-platform fix count: 155 vulnerabilities.
  • One flaw, CVE-2026-43810, allows a remote attacker to corrupt kernel memory, which is the deepest, most privileged layer of the operating system.
  • watchOS, tvOS, and visionOS each received patches for roughly 100 vulnerabilities.
  • Apple's advisories confirm none of the flaws are known to be actively exploited right now.

Apple has shipped software updates covering hundreds of security vulnerabilities across every major platform it makes: iPhones, iPads, Macs, Apple Watches, Apple TVs, and Vision Pro headsets.

The patches arrived Monday with no prior warning, which is standard Apple practice.

How bad are these flaws?

None are confirmed as actively exploited in the wild. That is genuinely reassuring, but the sheer variety of what the flaws could allow, if left unpatched, is worth understanding.

Across iOS 26 and iPadOS 26, Apple fixed 87 vulnerabilities. The possible consequences included: apps reading private data they should never see, attackers running their own code on your device, and an intruder adding contacts or spoofing the screen interface without your permission.

macOS Tahoe 26.6 topped the list with 155 fixes. Two older Mac operating systems also got updates: macOS Sequoia 15.7.8 with 138 fixes, and macOS Sonoma 14.8.8 with 127.

Platform Update version Vulnerabilities fixed
iOS and iPadOS 26.6 87
macOS Tahoe 26.6 155
macOS Sequoia 15.7.8 138
macOS Sonoma 14.8.8 127
watchOS / tvOS / visionOS various ~100 each
Safari latest ~12

Which flaw deserves the closest attention?

One stands out. CVE-2026-43810 lets a remote user, meaning someone who does not have physical access to your device, corrupt kernel memory. The kernel is the innermost part of the operating system; it controls everything else. Corrupting it can give an attacker total control.

Adam Boynton, senior enterprise strategy manager at device-management firm Jamf, put it plainly: "Remote changes the economics of an attack chain considerably." In other words, a flaw that requires physical device access is hard to exploit at scale. One that works over a network is not.

Safari, Apple's web browser, also received roughly a dozen fixes, including flaws that could expose private user data or crash the browser outright.

What should iPhone and Mac users actually do?

Update now. Go to Settings, then General, then Software Update on an iPhone or iPad. On a Mac, open System Settings and click General, then Software Update.

If you use an older Mac running Sequoia or Sonoma rather than Tahoe, updates are still available for you; Apple patched all three macOS generations. Do not assume that running older hardware means you are left behind here.

Watch and TV users should check for updates in their device settings too. The fix counts there are just as large.

There is no evidence criminals are actively using any of these flaws today. Applying the update before that changes costs you five minutes. Waiting costs considerably more if the calculation ever shifts.

© 2026 Threat Vectr