Apple Ships iOS 26.6 With 90 Security Fixes as WebKit, Kernel Flaws Raise Spyware Risk
Updated
Updated · Forbes · Jul 28
Apple Ships iOS 26.6 With 90 Security Fixes as WebKit, Kernel Flaws Raise Spyware Risk
3 articles · Updated · Forbes · Jul 28
Summary
Nearly 90 fixes in iOS 26.6 target WebKit, kernel and ImageIO vulnerabilities, with experts urging rapid installation because browser-engine bugs are the most likely to be weaponized.
WebKit flaw CVE-2026-64730 could enable UI spoofing from malicious framed websites, while kernel bugs include CVE-2026-64735 for bypassing network filters and CVE-2026-43810, a remote kernel-memory corruption risk.
ImageIO bug CVE-2026-43818 could let a crafted image trigger arbitrary code execution, a class of weakness researchers say can feed targeted spyware chains against executives, journalists and other high-value users.
User reports suggest 26.6 also fixes some battery drain and overheating seen in iOS 26.5.2, though results appear mixed across devices; the release adds few features beyond groundwork for Siri-related indexing in iOS 27.
Apple issued parallel updates for iPad, Mac, Apple TV, Watch, Vision Pro and Safari, but no iOS 18 security release for older iPhones accompanied the rollout.