VYPR
Vypr IntelligenceAI-generatedJul 27, 2026· 25 CVEs

Apple iOS 26.6: 25 Vulnerabilities Patched, Including Memory Corruption and Sandbox Escapes

Apple patched 25 vulnerabilities in iOS 26.6 and other operating systems on July 27, 2026, addressing issues ranging from memory corruption to sandbox escapes.

Key findings

  • Apple released iOS 26.6 and other OS updates on July 27, 2026, patching a batch of 25 vulnerabilities.
  • Vulnerabilities include memory corruption, sandbox escapes, and unauthorized data access across multiple Apple operating systems.
  • Several flaws could lead to unexpected system termination, kernel memory corruption, or arbitrary code execution.
  • The fixes are available in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, and other related OS versions.
  • No active exploitation was reported by Apple at the time of disclosure for this batch.

On July 27, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities across its iOS, iPadOS, macOS, tvOS, visionOS, and watchOS operating systems. The vulnerabilities, disclosed on the same day, span a range of issues including memory corruption, sandbox escapes, and unauthorized data access, with fixes available in iOS 26.6 and iPadOS 26.6, among others. These patches are crucial for users to protect against potential system termination, kernel memory corruption, and arbitrary code execution.

Several vulnerabilities stem from memory management issues. CVE-2026-43673, CVE-2026-64716, and CVE-2026-64726 involve processing maliciously crafted files or images that could corrupt process memory. Use-after-free vulnerabilities, such as CVE-2026-64783, CVE-2026-43799, and CVE-2026-64700, could lead to unexpected system termination when processing malicious web content or other crafted data. Additionally, race conditions, including CVE-2026-43805 and CVE-2026-64720, could allow an app to cause unexpected system termination.

Other vulnerabilities focus on bypassing security restrictions and gaining unauthorized access. CVE-2026-64740 describes a parsing issue that could allow a malicious app to break out of its sandbox. CVE-2026-43813, a validation issue, could enable a malicious app to bypass code signing enforcement. Permissions issues are also prevalent, with CVE-2026-64741 allowing an app to read a persistent device identifier, CVE-2026-64707 enabling an app to delete files without permission, and CVE-2026-43730 permitting an app to fingerprint the user. CVE-2026-64746 presents an authorization issue where an app could add contacts without user consent, and CVE-2026-64711 could allow an app to leak sensitive user information.

Several vulnerabilities carry the risk of arbitrary code execution or kernel-level access. CVE-2026-43776, a buffer overflow, could lead to unexpected app termination or arbitrary code execution when processing a maliciously crafted file. Similarly, CVE-2026-28931, another buffer overflow, could result in kernel memory corruption when connecting to a malicious NFS server. CVE-2026-64766, an integer overflow, and CVE-2026-64771, a buffer overflow, could also lead to unexpected application termination or heap corruption. CVE-2026-64721, addressed with improved state management, could allow an app to access sensitive user data.

The batch of vulnerabilities was fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Users are strongly advised to update their devices to the latest versions to mitigate these security risks. While Apple did not label any of these specific vulnerabilities as being exploited in the wild at the time of disclosure, the broad impact across multiple operating systems underscores the importance of timely patching.

This coordinated disclosure highlights Apple's ongoing efforts to address a wide array of security weaknesses across its ecosystem. The variety of issues, from memory corruption to permission escalations, emphasizes the need for continuous vigilance and regular software updates for all Apple device users. Staying updated ensures protection against potential exploits that could compromise user data and system integrity. ,cve_ids=[

AI-written article. Grounded in 25 CVE records listed below.