Updated
Updated · Forbes · Jul 28
Apple Ships iOS 26.6 With 90 Security Fixes as WebKit, Kernel Flaws Raise Spyware Risk
Updated
Updated · Forbes · Jul 28

Apple Ships iOS 26.6 With 90 Security Fixes as WebKit, Kernel Flaws Raise Spyware Risk

3 articles · Updated · Forbes · Jul 28

Summary

  • Nearly 90 fixes in iOS 26.6 target WebKit, kernel and ImageIO vulnerabilities, with experts urging rapid installation because browser-engine bugs are the most likely to be weaponized.
  • WebKit flaw CVE-2026-64730 could enable UI spoofing from malicious framed websites, while kernel bugs include CVE-2026-64735 for bypassing network filters and CVE-2026-43810, a remote kernel-memory corruption risk.
  • ImageIO bug CVE-2026-43818 could let a crafted image trigger arbitrary code execution, a class of weakness researchers say can feed targeted spyware chains against executives, journalists and other high-value users.
  • User reports suggest 26.6 also fixes some battery drain and overheating seen in iOS 26.5.2, though results appear mixed across devices; the release adds few features beyond groundwork for Siri-related indexing in iOS 27.
  • Apple issued parallel updates for iPad, Mac, Apple TV, Watch, Vision Pro and Safari, but no iOS 18 security release for older iPhones accompanied the rollout.

Insights

Why does Apple still force strict charging rules for minor watchOS 26.6 updates when other smart devices update seamlessly?
What critical security flaws is Apple hiding behind the seemingly routine bug fixes in the new watchOS 26.6 release?
Are your third-party chargers secretly degrading your Apple Watch battery while you install the new watchOS 26.6 update?