Connect with us

Mobile Tech

Critical Security Update: Apple Patches 75+ iPhone and 150+ Mac Vulnerabilities – Protect Your Devices Now!

Published

on

iOS 26.6.1 likely coming soon as Apple speeds up iPhone updates

With the recent release of iOS 26.6 and iPadOS 26.6, Apple has unveiled a multitude of security enhancements embedded in these latest operating system updates.

Implications of Apple’s Security Updates in iOS 26.6 and iPadOS 26.6 on iPhone and iPad

Spanning across iOS 26.6 and iPadOS 26.6, Apple has meticulously outlined over 75 security patches aimed at fortifying the iPhones and iPads. These fixes encompass a wide array of system components.

To be specific, Apple’s security advisory encompasses 78 distinct vulnerability entries linked to 87 unique CVE numbers. The CVE count is inflated as some entries address multiple CVEs simultaneously.

Apple has not disclosed any instances of the vulnerabilities patched in iOS 26.6 being actively exploited in the wild.

Among the extensive list of fixes provided by Apple, several notable ones include:

  • An exploit in MediaRemote that could grant an application root privileges.
  • A vulnerability in AVEVideoEncoder enabling an app to execute arbitrary code with kernel privileges.
  • Security loopholes in Game Center and libc facilitating a malicious app to escape its sandbox.
  • A CloudAttestation flaw allowing a malicious app to circumvent code-signing enforcement.
  • An ImageIO vulnerability potentially leading to arbitrary code execution during the processing of a malevolent image.
  • Three SceneKit vulnerabilities that could result in arbitrary code execution when handling maliciously crafted files.
  • An Accessibility issue that might expose sensitive data through iPhone Mirroring to individuals with physical access.
  • A Contacts flaw enabling an app to add contacts without user consent.

Enhancements in Kernel, WebKit, and Wi-Fi

Apple has also rectified over a dozen kernel vulnerabilities, encompassing potential risks such as corrupting or writing to kernel memory, disclosing kernel memory, bypassing network filters, and triggering unexpected system termination.

Furthermore, WebKit has received a substantial array of fixes addressing vulnerabilities that could expose process memory, unveil visited links, enable interface spoofing, violate iframe sandboxing rules, allow an app to read files outside its sandbox, or crash Safari.

Additionally, a Wi-Fi vulnerability has been mitigated that could have allowed a nearby attacker to corrupt process memory.

Following the 78 documented security patches, Apple has furnished a separate section titled “Additional recognition,” acknowledging the contributions of 12 researchers. These entries commend the researchers for their aid but are not classified as distinct security fixes or assigned additional CVE numbers.

For a comprehensive list of fixes and researcher credits, users can refer to Apple’s official website.

Security Enhancements for Mac, Apple Watch, Apple TV, and Apple Vision Pro

Apple’s latest security notes for macOS Tahoe 26.6 delineate 155 unique CVEs.

In addition to numerous shared fixes with iPhone and iPad, the Mac update addresses vulnerabilities that could empower apps to gain root access, evade their sandboxes, bypass Gatekeeper checks or privacy preferences, and access protected data.

Furthermore, Apple has rolled out security updates for older macOS versions today, albeit they are not encompassed in the aforementioned counts.

Notably, Apple has elaborated on fixes for watchOS 26.6, tvOS 26.6, and visionOS 26.6, with the latest updates addressing 194 unique CVEs post eliminating overlap between platforms.

Apple had previously disclosed its hastened release of several security fixes in the preceding iOS 26.5.2 update in response to AI-driven hacking tools.

Add 9to5Mac as a preferred source on Google
Add 9to5Mac as a preferred source on Google

FTC: We use income earning auto affiliate links. More.

See also  Uncovering the Vulnerabilities of VolkLocker Ransomware: Master Key Flaw Allows for Decryption

Trending