{"id":343168,"date":"2025-12-13T19:22:11","date_gmt":"2025-12-13T19:22:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/343168\/"},"modified":"2025-12-13T19:22:11","modified_gmt":"2025-12-13T19:22:11","slug":"ios-26-2-update-now-warning-issued-to-all-iphone-users","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/343168\/","title":{"rendered":"iOS 26.2\u2014Update Now Warning Issued To All iPhone Users"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2025\/12\/1765653731_35_0x0.jpg\" alt=\"Apple iOS 26.2 update displayed on an iPhone 16 Pro screen\" data-height=\"763\" data-width=\"1067\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Screenshot iOS 26.2 fixes 26 flaws in Apple\u2019s iOS software, two of which are already being used in real-life attacks.<\/p>\n<p>Apple iPhone<\/p>\n<p>Update Dec. 13 at 03:35 a.m. EST: This article, originally published at 04:03 a.m. EST has been updated to add expert comment on the flaws fixed in iOS 26.2, as well as detailing why there was no iOS 26.1.1.<\/p>\n<p>Apple has released <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/12\/04\/ios-262-apple-gives-iphone-users-3-new-reasons-to-update-from-ios-18\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/12\/04\/ios-262-apple-gives-iphone-users-3-new-reasons-to-update-from-ios-18\/\" target=\"_self\" aria-label=\"iOS 26.2\" rel=\"nofollow noopener\">iOS 26.2<\/a>, along with a warning to <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/12\/05\/check-your-iphone-now-these-models-will-no-longer-receive-updates\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/12\/05\/check-your-iphone-now-these-models-will-no-longer-receive-updates\/\" target=\"_self\" aria-label=\"update your iPhone\" rel=\"nofollow noopener\">update your iPhone<\/a> now. That\u2019s because iOS 26.2 fixes 26 flaws in Apple\u2019s iOS software, two of which are already being used in real-life attacks.<\/p>\n<p>Apple doesn\u2019t provide much detail about what\u2019s fixed in iOS 26.2, to give iPhone users as much time as possible to update before attackers can get hold of the details. But it does reveal that iOS 26.2 fixes two flaws in WebKit, the engine that underpins the Safari browser, that \u201cmay have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26.\u201d <\/p>\n<p>Tracked as CVE-2025-43529 and <a class=\"color-link\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-14174\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cve.org\/CVERecord?id=CVE-2025-14174\" aria-label=\"CVE-2025-14174\">CVE-2025-14174<\/a>, the two already exploited issues fixed in iOS 26.2 are related. The first flaw could lead to arbitrary code execution, if a user interacts with maliciously crafted web content. \u201cCVE-2025-14174 was also issued in response to this report,\u201d Apple said on its <a class=\"color-link\" href=\"https:\/\/support.apple.com\/en-gb\/125884\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.apple.com\/en-gb\/125884\" aria-label=\"support page\">support page<\/a>.<\/p>\n<p>Apple\u2019s iOS 26. 2 also fixes a vulnerability in the iPhone Kernel, tracked as CVE-2025-46285, which could allow an app to gain root privileges.<\/p>\n<p>If an attacker gains root access on a phone, they \u201ceffectively own it,\u201d bypassing app sandboxes, reading messages and login codes and hijacking banking sessions, says Javvad Malik, lead CISO advisor at KnowBe4.<\/p>\n<p>Criminals weaponise newly patched flaws quickly, he warns. \u201cUsers should update now from their phone\u2019s settings \u2014 and not via links or popups \u2014 and encourage their friends and family to do the same.\u201d<\/p>\n<p>iOS 26.2 Comes Alongside Reports Of iPhone Spyware<\/p>\n<p>The release of iOS 26.2 comes as Apple confirms its devices are being <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/12\/08\/apple-issues-new-spyware-attack-warning-to-iphone-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/12\/08\/apple-issues-new-spyware-attack-warning-to-iphone-users\/\" target=\"_self\" aria-label=\"targeted by spyware\" rel=\"nofollow noopener\">targeted by spyware<\/a>. The iPhone maker sent out <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/05\/01\/apple-issues-new-spyware-attack-warning-to-iphone-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/05\/01\/apple-issues-new-spyware-attack-warning-to-iphone-users\/\" target=\"_self\" aria-label=\"cyber threat notifications\" rel=\"nofollow noopener\">cyber threat notifications<\/a> to users in at least 80 countries warning them that they are being targeted by the stealthy malware.<\/p>\n<p>Spyware is extremely targeted and aimed at a certain subset of iPhone users, including dissidents, journalists and businesses operating in certain sectors. However, once it is on your device it can see and hear everything you do, even via encrypted apps such as WhatsApp.<\/p>\n<p>Why Apple Let The Patch Wait Until iOS 26.2 <\/p>\n<p>As eagled-eyed iPhone security watchers may have noticed, Apple has waited until iOS 26.2 to issue this emergency update, rather than releasing iOS 26.1.1 as a security-only upgrade.<\/p>\n<p>This is because Apple has already enabled a feature in <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/11\/14\/ios-261-or-ios-1872-heres-which-new-iphone-update-to-choose\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/11\/14\/ios-261-or-ios-1872-heres-which-new-iphone-update-to-choose\/\" target=\"_self\" aria-label=\"iOS 26.1\" rel=\"nofollow noopener\">iOS 26.1<\/a>. called Background Security Improvements, which performs these updates on the fly. If you have upgraded to iOS 26.1 and enabled this feature, your iPhone will already be protected from this possible spyware attack.<\/p>\n<p>This also explains why Apple is pushing iOS 26.1 as the update to choose, rather than iOS 18. If you have failed to update from iOS 26 to iOS 26.1, moving straight to iOS 26.2 is therefore a no-brainer. <\/p>\n<p>Flaws Fixed in iOS 26.2 Could Be Part Of Wider Attack Chain<\/p>\n<p>The issues fixed in iOS 26.2 could be part of a wider attack chain, says Darren Guccione, CEO and co-founder of Keeper Security. Attackers can chain together multiple flaws to bypass layers of device security, combining zero-days or exploiting overlooked weaknesses in critical components, he says. \u201cWebKit, which is a fundamental element of every iPhone browser, continues to be a prime target because it sits at the intersection of web content and the operating system.\u201d<\/p>\n<p>When vulnerabilities like these are disclosed and patches are issued, timing matters, Guccione warns. \u201cOnce Apple issues a fix, details about the vulnerabilities quickly become public, giving attackers a roadmap to exploit any devices that have not yet been patched. The longer users wait, the greater the risk.\u201d<\/p>\n<p>WebKit flaws like the ones fixed in iOS 26.2 are especially dangerous because they \u201csit at the crossroads of user interaction, browser execution and the underlying APIs,\u201d says Glyn Morgan, UK&amp;I manager at Salt Security. \u201cWhen WebKit flaws are exploited they can bypass controls and enable deep surveillance even on encrypted apps.\u201d<\/p>\n<p>The Kernel flaw fixed in iOS 26.2 is also serious because the Kernel \u201csits at the very core of the operating system,\u201d says Jake Moore, global cybersecurity advisor at ESET. \u201cIf exploited, it could allow a malicious payload to escalate privileges, effectively breaking out of the normal app boundaries to gain higher level access.\u201d<\/p>\n<p>Why You Should Update Your iPhone to iOS 26.2 Now <\/p>\n<p>Apple\u2019s iOS 26.2 also comes with a number of cool new features, many of which offer a boost to your iPhone\u2019s security. In iOS 26.2, Apple will add improvements to Enhanced Safety Alerts.<\/p>\n<p>Apple\u2019s iOS 26.2 also adds new options for the controversial Liquid Glass feature, Podcast enhancements, offline lyric support in Apple Music, sleep score revisions, alarms for reminders and AirPods Live Translation in the EU.<\/p>\n<p>It is notable that both WebKit issues patched in iOS 26.2 were exploited in versions before iOS 26, making it integral that you upgrade your iPhone now. Apple has issued iOS 18.7.3 alongside iOS 26.2, which means you can update your iPhone and fix the dangerous flaws if you prefer to stay on an older version. <\/p>\n<p>So, what are you waiting for? Go to your Settings &gt; General &gt; Software Update and update to iOS 26.2 or iOS 18.7.3 now.<\/p>\n","protected":false},"excerpt":{"rendered":"Screenshot iOS 26.2 fixes 26 flaws in Apple\u2019s iOS software, two of which are already being used in&hellip;\n","protected":false},"author":2,"featured_media":343169,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[49,48,149892,149891,149887,146267,149889,149890,146265,149888,146264,190,149886,61],"class_list":{"0":"post-343168","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-ca","9":"tag-canada","10":"tag-cve-2025-14174","11":"tag-cve-2025-43529","12":"tag-ios-26-2-bugs","13":"tag-ios-26-2-release","14":"tag-ios-26-2-should-i-update","15":"tag-ios-26-2-should-i-upgrade","16":"tag-ios-26-2-update","17":"tag-ios-26-2-upgrade","18":"tag-is-ios-26-2-safe","19":"tag-mobile","20":"tag-should-i-update-to-ios-26-2","21":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/343168","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=343168"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/343168\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/343169"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=343168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=343168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=343168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}