{"id":848451,"date":"2026-09-15T09:14:28","date_gmt":"2026-09-15T09:14:28","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/848451\/"},"modified":"2026-09-15T09:14:28","modified_gmt":"2026-09-15T09:14:28","slug":"heres-every-security-fix-included-in-ios-27-and-ipados-27","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/848451\/","title":{"rendered":"Here\u2019s every security fix included in iOS 27 and iPadOS 27"},"content":{"rendered":"<p>Between the official release of its 2027 operating system updates, point updates to previous operating systems, and standalone updates to Safari and Xcode, Apple today rolled out security fixes across dozens of devices.<\/p>\n<p>When it comes to iOS 27 and iPadOS 27, Apple\u2019s <a href=\"https:\/\/support.apple.com\/en-us\/149034\" rel=\"nofollow noopener\" target=\"_blank\">security content page<\/a> lists more than 120 fixes, some of which address vulnerabilities that could allow attackers or malicious apps to execute arbitrary code, gain kernel or root privileges, access sensitive user data, bypass system protections, and more.<\/p>\n<p>Accelerate Framework<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted image may lead to unexpected process termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86882: Peter Malone<\/p>\n<p>Accessibility<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: This issue was addressed with improved data protection.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43664: Stuart Wallace, Ilya Andr (andrd3v), Rosyna Keller of Totally Not Malicious Software, CJ Vana, David Strnadel, Daniel Febrero, Asaf Cohen, Gongyu Ma (@Mezone0), Jian Lee (@speedyfriend433)<\/p>\n<p>Accessibility<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to identify what other apps a user has installed<\/p>\n<p class=\"wp-block-paragraph\">Description: A privacy issue was addressed with improved handling of user preferences.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-64761: Stuart Wallace, Sindre Sorhus<\/p>\n<p>Accounts<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A malicious application may be able to bypass Privacy preferences<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65404: Arni Hardarson (Neonix Security), Vinay Kumar Rasala (Xplo8E) from Appknox, Stuart Wallace, \uc774\uc7ac\uc601<\/p>\n<p>APFS<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination or write kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84523: Cem Onat Karagun, an anonymous researcher<\/p>\n<p>App Store<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A local app may be able to read a persistent account identifier<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86888: Zhongcheng Li (CK01)<\/p>\n<p>Apple Account<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to use the Sign In With Apple authentication flow to access the user\u2019s Apple Account<\/p>\n<p class=\"wp-block-paragraph\">Description: An authentication issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-20683: Dem0ns (@\u5929\u5e9c\u7b80\u6613\u4fe1\u5de5\u4f5c\u5ba4), Abdelhak Kherroubi, Jasminder Pal Singh, Lehan Dilusha Jayasingha (Sri Lanka)<\/p>\n<p>Apple Neural Engine<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An integer overflow was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65408: tamdao<\/p>\n<p>AppleAVD<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A use after free issue was addressed with improved memory management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65407: Franco Belman at Blackwing Intelligence<\/p>\n<p>AppleDouble<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Mounting a disk image with maliciously crafted files may lead to unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84519: Richard Zana<\/p>\n<p>AppleKeyStore<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A use after free issue was addressed with improved memory management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84593: Meta Red Team X \u2013 Nik Tsytsarkin, Alexandre Borges<\/p>\n<p>Authentication Services<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to delete credentials stored in Keychain<\/p>\n<p class=\"wp-block-paragraph\">Description: This issue was addressed by removing the vulnerable code.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86905: Ilya Andr (andrd3v)<\/p>\n<p>AuthKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A local app may be able to read a persistent account identifier<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84583: Zhongcheng Li from IES Red Team<\/p>\n<p>AVEVideoEncoder<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: The issue was addressed with improved checks.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic Research<\/p>\n<p>AVEVideoEncoder<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A type confusion issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84616: Peter Malone<\/p>\n<p>AVEVideoEncoder<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A sandboxed app may be able to execute arbitrary code with kernel privileges<\/p>\n<p class=\"wp-block-paragraph\">Description: A race condition was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84607: Ruslan Dautov<\/p>\n<p>BackgroundAssets<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: A logic issue was addressed with improved validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security<\/p>\n<p>Baseband<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An attacker in radio range may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An input validation issue was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86885: Tuan D. Hoang, Hazem Issa, and Yongdae Kim @ KAIST SysSec Lab<\/p>\n<p>Baseband<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A remote attacker may be able to cause a denial-of-service<\/p>\n<p class=\"wp-block-paragraph\">Description: A denial-of-service issue was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86879: Hazem Issa and Yongdae Kim @ SysSec, KAIST<\/p>\n<p>Bluetooth<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65414<\/p>\n<p>Bluetooth<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may gain unauthorized access to Bluetooth<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84560: an anonymous researcher<\/p>\n<p>Camera<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86878: Sindre Sorhus, Ilya Andr (andrd3v) of Positive Technologies, Asaf Cohen<\/p>\n<p>CloudKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A local app may be able to read a persistent account identifier<\/p>\n<p class=\"wp-block-paragraph\">Description: An information disclosure issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86895: Stanislav Jelezoglo<\/p>\n<p>CloudKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to read device name<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86893: Heiner Gerdes<\/p>\n<p>copyfile<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An archive may be able to bypass Gatekeeper<\/p>\n<p class=\"wp-block-paragraph\">Description: A file quarantine bypass was addressed with additional checks.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65399: Rishabh Jain (rjcyber) of cyberplanet, Pasquale Scola, an anonymous researcher<\/p>\n<p>CoreMedia<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted image may lead to arbitrary code execution<\/p>\n<p class=\"wp-block-paragraph\">Description: A memory corruption issue was addressed by removing the vulnerable code.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-64752: Nik Tsytsarkin<\/p>\n<p>CoreMedia<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A sandboxed process may be able to circumvent sandbox restrictions<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86876: Chris Bailey \u2013 Short Circuit<\/p>\n<p>CoreMedia<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted video file may lead to unexpected app termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65344: Siyeong kim<\/p>\n<p>CoreML<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A sandboxed app may be able to access restricted files<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with improved path validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84624: AL Najafi, tamdao<\/p>\n<p>CoreMotion<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access motion data from headphones without user consent<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43737: Stuart Wallace<\/p>\n<p>CoreText<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing web content may lead to a denial-of-service<\/p>\n<p class=\"wp-block-paragraph\">Description: A null pointer dereference was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65412: Pavan Nallamothu<\/p>\n<p>CoreText<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted font may result in the disclosure of process memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds read was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84596: ret2happy, Meta Product Security<\/p>\n<p>CoreUI<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted file may lead to unexpected app termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re)<\/p>\n<p>CoreUI<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause a denial of service<\/p>\n<p class=\"wp-block-paragraph\">Description: A buffer overflow was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84489: stratan (@5tratan), Peter Malone<\/p>\n<p>CoreUI<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted image may lead to unexpected app termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A buffer overflow was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84571: stratan (@5tratan), Peter Malone<\/p>\n<p>CoreUI<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted asset catalog may result in disclosure of process memory<\/p>\n<p class=\"wp-block-paragraph\">Description: The issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43738: Peter Malone<\/p>\n<p>CoreUI<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted asset catalog may lead to unexpected process termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84511: Rahul Raj, stratan (@5tratan)<\/p>\n<p>DeviceCheck<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to read persistent device identifiers<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved access control.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill (@jjtech@infosec.exchange)<\/p>\n<p>Disk Images<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: The issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84552: Tommy DeVoss from Braze Security Team (@thedawgyg), flower xu, Adriatik Raci, PETOWORKS\uc758 Bugeun Choi (@Bugeun), Peter Malone, Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research), Hyunwoo Kim (@v4bel)<\/p>\n<p>exFAT<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Mounting a maliciously crafted volume may lead to unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A heap buffer overflow was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84510: Meta Red Team X \u2013 Nik Tsytsarkin, Richard Zana<\/p>\n<p>File Bookmark<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to modify a file it only had permission to read<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43785: Junyeong Lee (jylab.github.io), Merrick Hare, Aditya Kumar, John Nzyuko Uvyu, Narendra Singh (@_3P1C)<\/p>\n<p>file_cmds<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Extracting a maliciously crafted archive may allow an attacker to write arbitrary files<\/p>\n<p class=\"wp-block-paragraph\">Description: A path handling issue was addressed with improved validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84534: Geoffrey Lovelace<\/p>\n<p>Filters<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted file may lead to unexpected app termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A memory corruption issue was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43688: Peter Malone<\/p>\n<p>FontParser<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted font file may lead to unexpected app termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds read was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84524: an anonymous researcher<\/p>\n<p>FontParser<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted font may result in the disclosure of process memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds read issue was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84597: Nik Tsytsarkin<\/p>\n<p>Foundation<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause a denial of service<\/p>\n<p class=\"wp-block-paragraph\">Description: A type confusion issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research<\/p>\n<p>Graphics<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A race condition was addressed with improved state handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg), Jiyong Yang<\/p>\n<p>Heimdal<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An attacker in a privileged network position may be able to modify network traffic<\/p>\n<p class=\"wp-block-paragraph\">Description: A cryptographic issue was addressed with improved integrity checks.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84533: Vishal Patidar, Roman Zabicki<\/p>\n<p>iCloud<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to identify a user across reinstalls<\/p>\n<p class=\"wp-block-paragraph\">Description: A privacy issue was addressed with improved handling of identifiers.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84606: Ilya Andr (andrd3v)<\/p>\n<p>Image Capture<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access user-sensitive data<\/p>\n<p class=\"wp-block-paragraph\">Description: A path handling issue was addressed with improved validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-64756: Luke Symons<\/p>\n<p>ImageIO<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted image may result in disclosure of process memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An uninitialized memory issue was addressed with improved memory initialization.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84564: Justin O\u2019Leary<\/p>\n<p>ImageIO<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted image may result in memory corruption<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan<\/p>\n<p>IOKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A use after free issue was addressed with improved memory management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, \uc774\uc7ac\uc601<\/p>\n<p>IOMobileFrameBuffer<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination or corrupt kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds access issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65398: Chris Bailey \u2013 Short Circuit, Mustafa Calap (@ordinal0, dbg.re), David Strnadel, Meta Red Team X \u2013 Nik Tsytsarkin<\/p>\n<p>IOSurfaceAccelerator<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to leak sensitive kernel state<\/p>\n<p class=\"wp-block-paragraph\">Description: An information leakage was addressed with additional validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-64760: an anonymous researcher, Seiji Sakurai (@HeapSmasher), Franco Belman at Blackwing Intelligence<\/p>\n<p>iWork<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A malicious app may be able to break out of its sandbox<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65354: Csaba Fitzl (@theevilbit) of Iru<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination or corrupt kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-28968: genter0, Svetoslav Stolarov &amp; Aisa Fox, Josh Maine of Calif.io, Dun<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A local attacker may be able to cause unexpected system termination or corrupt kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: The issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84566: Bernhard Jackiewicz<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A local user may be able to cause unexpected system termination or read kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: A race condition was addressed with additional validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65415: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ryan Hileman via Xint Code (xint.io)<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination or corrupt kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: A double free issue was addressed with improved memory management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A race condition was addressed with improved state handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A memory corruption issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65377: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ye Zhang (@VAR10CK) of Baidu Security<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app with root privileges may be able to read uninitialized kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: A memory initialization issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.)<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A malicious app may be able to gain root privileges<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43689: Andreas Jaegersberger &amp; Ro Achterberg of Nosebeard Labs<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Connecting to a malicious NFS server may disclose kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: The issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43687: R4mbb of KRsecurity, Peter Malone<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Connecting to a malicious NFS server may lead to kernel memory corruption<\/p>\n<p class=\"wp-block-paragraph\">Description: A use-after-free issue was addressed with improved memory management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43686: Peter Malone<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to determine kernel memory layout<\/p>\n<p class=\"wp-block-paragraph\">Description: A memory initialization issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to disclose kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An information disclosure issue was addressed with improved memory management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84530: Vladislav Shevchenko (Positive Technologies)<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A use after free issue was addressed with improved memory management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84521: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65402: F\u00e1bio Lu\u00eds @scanpt, Richard Zana, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A local user may be able to cause unexpected system termination or read kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds read was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination or corrupt kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: A race condition was addressed with improved state handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to disclose kernel memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds read was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86903: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A type confusion issue was addressed with improved checks.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.<\/p>\n<p>libarchive<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted file may lead to unexpected app termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A heap buffer overflow was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86870: Kitten Food<\/p>\n<p>Managed Configuration<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: A privacy issue was addressed with improved handling of files.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86883: Sindre Sorhus, Morris Richman (@morrisinlife), Stuart Wallace, Tristan Brennan<\/p>\n<p>MediaRemote<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A sandboxed app may be able to access the System Keychain<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84628: Myeonghun Pak, Nathaniel Oh (@calysteon), Alan Banderas (@creeper4004)<\/p>\n<p>MobileAccessoryUpdater<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Connecting a malicious accessory may cause unexpected system termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A memory corruption issue was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86924: Matthew Zamat<\/p>\n<p>MobileBackup<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to modify protected parts of the file system<\/p>\n<p class=\"wp-block-paragraph\">Description: A path handling issue was addressed with improved validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65411: Rodolphe Brunetti (@eisw0lf) of Lupus Nova<\/p>\n<p>MobileBackup<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An attacker with physical access to a trust-paired device may be able to read and write arbitrary files<\/p>\n<p class=\"wp-block-paragraph\">Description: A path traversal issue was addressed with improved path validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84598: Drin Raci of sentry.security<\/p>\n<p>Model I\/O<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Opening a maliciously crafted file may lead to unexpected process termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A buffer overflow was addressed with improved size validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84497: Yi\u011fit Can YILMAZ (@yilmazcanyigit)<\/p>\n<p>Music<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84615: Stanislav Jelezoglo<\/p>\n<p>NetworkExtension<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos<\/p>\n<p>NetworkExtension<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to identify what other apps a user has installed<\/p>\n<p class=\"wp-block-paragraph\">Description: An information disclosure issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team<\/p>\n<p>Photos Storage<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84491: an anonymous researcher<\/p>\n<p>Photos Storage<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to fingerprint the user<\/p>\n<p class=\"wp-block-paragraph\">Description: This issue was addressed with additional entitlement checks.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84629: Stanislav Jelezoglo<\/p>\n<p>Power Management<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to fingerprint the device<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84623: Ilya Andr (andrd3v)<\/p>\n<p>RealityKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted file may lead to unexpected app termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-28966: stratan (@5tratan)<\/p>\n<p>RealityKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Opening a maliciously crafted file may cause unexpected process termination or disclose process memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds read issue was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84532: Hongsik Kim (mnur), stratan (@5tratan)<\/p>\n<p>Reminders<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: This issue was addressed with improved checks.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65403: Rahul Raj<\/p>\n<p>Safari<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A malicious website may be able to determine what apps a user has installed<\/p>\n<p class=\"wp-block-paragraph\">Description: This issue was addressed through improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84518: B\u00e1lint Magyar (balintmagyar.com)<\/p>\n<p>Safe Browsing<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: This issue was addressed with additional entitlement checks.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86897: Stuart Wallace<\/p>\n<p>Sandbox<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to bypass network restrictions<\/p>\n<p class=\"wp-block-paragraph\">Description: A logic issue was addressed with improved validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84551: Issa Sancho<\/p>\n<p>Sandbox Profiles<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to fingerprint the user<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional sandbox restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84625: Ilya Andr (andrd3v) of Positive Technologies, CJ Vana<\/p>\n<p>Sandbox Profiles<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84603: Gongyu Ma (@Mezone0), CJ Vana, Stanislav Jelezoglo<\/p>\n<p>SceneKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted file may result in disclosure of process memory<\/p>\n<p class=\"wp-block-paragraph\">Description: An integer overflow was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84487: stratan (@5tratan), Dhiyanesh Selvaraj (@redroot97), Peter Malone<\/p>\n<p>SceneKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted 3D model may lead to memory corruption<\/p>\n<p class=\"wp-block-paragraph\">Description: The issue was addressed with improved memory handling.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84632: Peter Malone<\/p>\n<p>SceneKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted 3D model may lead to memory corruption<\/p>\n<p class=\"wp-block-paragraph\">Description: An integer overflow was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84620: Peter Malone<\/p>\n<p>SceneKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted 3D model may lead to memory corruption<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter Malone<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84611: Nathaniel Oh (@calysteon)<\/p>\n<p>SceneKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing a maliciously crafted 3D scene may lead to unexpected process termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84526: stratan (@5tratan)<\/p>\n<p>Security<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages<\/p>\n<p class=\"wp-block-paragraph\">Description: A certificate validation issue was addressed with improved certificate validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier, Filip Olszak<\/p>\n<p>Security<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing maliciously crafted NTLM input may lead to unexpected app termination<\/p>\n<p class=\"wp-block-paragraph\">Description: An out-of-bounds write issue was addressed with improved bounds checking.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84531: Meshaal (@unrealmesh)<\/p>\n<p>Shortcuts<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A malicious shortcut may be able to send messages without user confirmation<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84600: Owen Pawling (@owenpawling)<\/p>\n<p>Siri<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86884: Stanislav Jelezoglo, Gongyu Ma (twitter @Mezone0)<\/p>\n<p>Siri Suggestions<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An attacker with physical access to a locked device may be able to view sensitive user information<\/p>\n<p class=\"wp-block-paragraph\">Description: A logic issue was addressed with improved checks.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86890: Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India<\/p>\n<p>Software Update<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to modify protected system files<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with improved path validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team<\/p>\n<p>Spotlight<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved access control.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84621: Abodi Dawoud, Armend Gashi, Ujjwal Reddy Kalvolu Sreenivasa Reddy, Johan Wahyudi<\/p>\n<p>SpringBoard<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to cause a denial-of-service<\/p>\n<p class=\"wp-block-paragraph\">Description: This issue was addressed with additional entitlement checks.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86892: Lehan Dilusha Jayasingha<\/p>\n<p>Storage<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to modify protected parts of the file system<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65348: J\u00e9r\u00f4me Djouder<\/p>\n<p>Storage<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access user-sensitive data<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed with additional restrictions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65345: Seung Je Seong, Ilya Andr (andrd3v) of Positive Technologies, Jakob Pammer, \uc774\uc7ac\uc601<\/p>\n<p>Symptom Framework<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: A malicious application may be able to determine a user\u2019s current location<\/p>\n<p class=\"wp-block-paragraph\">Description: A privacy issue was addressed with improved private data redaction for log entries.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84513: Sindre Sorhus<\/p>\n<p>TCC<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to modify protected system files<\/p>\n<p class=\"wp-block-paragraph\">Description: A path traversal issue was addressed with improved input validation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86886: Constantin Clerc, Shad J, huami1314 (@huamidev), Huy Nguyen (@34306) of Calif.io, an anonymous researcher<\/p>\n<p>TCC<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: A logging issue was addressed with improved data redaction.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84527: Zeyang Li&amp;Yuxiang Wang of Chongqing Telecom<\/p>\n<p>Telephony<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic<\/p>\n<p class=\"wp-block-paragraph\">Description: An authentication issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-65329: Bedran Karakoc, Tobias Funke, Jacopo Clark, Katharina Kohls of Ruhr University Bochum<\/p>\n<p>Time Zone<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to bypass certain Privacy preferences<\/p>\n<p class=\"wp-block-paragraph\">Description: A privacy issue was addressed by removing sensitive data.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86887: an anonymous researcher<\/p>\n<p>Watch App<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to track users across apps and websites without permission<\/p>\n<p class=\"wp-block-paragraph\">Description: A privacy issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86904: Stanislav Jelezoglo<\/p>\n<p>WebKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing maliciously crafted web content may lead to an unexpected process termination<\/p>\n<p class=\"wp-block-paragraph\">Description: A logic issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">WebKit Bugzilla: 310457<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84635: Souta Sugiyama<\/p>\n<p>WebKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing maliciously crafted web content may disclose sensitive user information<\/p>\n<p class=\"wp-block-paragraph\">Description: A permissions issue was addressed by removing the vulnerable code.<\/p>\n<p class=\"wp-block-paragraph\">WebKit Bugzilla: 315121<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-64753: Viggo Lekdorf<\/p>\n<p>WebKit<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Opening a maliciously crafted webarchive file may lead to universal cross-site scripting<\/p>\n<p class=\"wp-block-paragraph\">Description: A logic issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">WebKit Bugzilla: 3182711<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-86898: Tomi Garcia (archyxsec)<\/p>\n<p>WebKit Canvas<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash<\/p>\n<p class=\"wp-block-paragraph\">Description: A use-after-free issue was addressed with improved memory management.<\/p>\n<p class=\"wp-block-paragraph\">WebKit Bugzilla: 313935<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-64718: Niels Hofmans, OGINOME Tomohito, an anonymous researcher<\/p>\n<p>Wi-Fi3<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication<\/p>\n<p class=\"wp-block-paragraph\">Description: An authentication issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-43674: Yusuf Kelany<\/p>\n<p>Wi-Fi Connectivity<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84636: Jian Lee (@speedyfriend433)<\/p>\n<p>XPC<\/p>\n<p class=\"wp-block-paragraph\">Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later<\/p>\n<p class=\"wp-block-paragraph\">Impact: An app may be able to access sensitive user data<\/p>\n<p class=\"wp-block-paragraph\">Description: An authorization issue was addressed with improved state management.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-84617: Stuart Wallace<\/p>\n<p>Additional recognition<\/p>\n<p>Accessibility<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India for their assistance.<\/p>\n<p>Accounts<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Wojciech Regula of SecuRing (wojciechregula.blog) for their assistance.<\/p>\n<p>Apple Intelligence<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge an anonymous researcher for their assistance.<\/p>\n<p>AppleKeyStore<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Abdurrahman Nafi, Francisco Knabe, Karol Mazurek (@Karmaz95) of AFINE, Somair Ansar, YOKI, an anonymous researcher, \u6653\u5a1f \u8c22 for their assistance.<\/p>\n<p>Audio<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Dhiyanesh Selvaraj (@redroot97) for their assistance.<\/p>\n<p>AutoFill<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Bistrit Dahal, Oussama Barbar, SalahAldeen Yousef for their assistance.<\/p>\n<p>AVEVideoEncoder<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge tamdao for their assistance.<\/p>\n<p>Baseband<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Kai Tu, Tianchang Yang, Xiaotian Zhou, Ali Ranjbar, Abdullah Al Ishtiaq, Tianwei Wu, Yilu Dong, Syed Rafiul Hussain \u2014 SyNSec Lab at Penn State for their assistance.<\/p>\n<p>Bluetooth<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge David Maynor, Jason Grove, Suresh Sundaram, Youssef Ahmed Saad, jioundai for their assistance.<\/p>\n<p>BOM<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge 2ourc3 | Salim Largo for their assistance.<\/p>\n<p>Calendar<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Atul Kishor Jaiswal, Dany Assuid, Jacob Hazak from Zero-Defense Labs, Varik Matevosyan, stratan (@5tratan) for their assistance.<\/p>\n<p>CipherML<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Nils Hanff (@nils1729@chaos.social) of Hasso Plattner Institute for their assistance.<\/p>\n<p>CloudKit<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Ahmed Alwardani, Hikerell (Loadshine Lab) for their assistance.<\/p>\n<p>Contacts<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge \uc774\uc9c0\uc548 (@speedyfriend433) for their assistance.<\/p>\n<p>copyfile<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Morris Richman (@morrisinlife) and Jian Lee (@speedyfriend433) for their assistance.<\/p>\n<p>Core Location<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge CJ Vana for their assistance.<\/p>\n<p>CoreAnimation<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Duy Tr\u1ea7n (@khanhduytran0) for their assistance.<\/p>\n<p>CoreAudio<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Patrick Saif \/ x.com\/weezerOSINT \/ github.com\/sai2fast for their assistance.<\/p>\n<p>CoreBluetooth \u2013 LE<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Ashmit Sharma &amp; Atul RV, Dun, Maliq Barnard, Nicholas C. of Onymos Inc. (onymos.com), Peter Malone, Robert M for their assistance.<\/p>\n<p>CoreCrypto<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Lakshay Sharma for their assistance.<\/p>\n<p>CoreGraphics<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Gandalf4a of PKU-Changsha Institute for Computing and Digital Economy for their assistance.<\/p>\n<p>CoreMedia<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Chris Bailey \u2013 Short Circuit for their assistance.<\/p>\n<p>CoreText<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Chris Bailey \u2013 Short Circuit, Jian Lee (@speedyfriend433), shobhit srivastav for their assistance.<\/p>\n<p>CoreUI<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Peter Malone for their assistance.<\/p>\n<p>DataAccess<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Adetayo Adebimpe (Cyboghostginx) for their assistance.<\/p>\n<p>DiskArbitration<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Arni Hardarson (Neonix Security), FRO, Mustafa Ahmed, Thomas Guillem, \u4e5d\u5bab\u683c of Chongqing Telecom for their assistance.<\/p>\n<p>FaceTime<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Souhaib Naceri for their assistance.<\/p>\n<p>Files<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge an anonymous researcher for their assistance.<\/p>\n<p>Foundation<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Daniel Luedke, Pavan Nallamothu, Peter Malone, Tiago \u201cBalgan\u201d Henriques for their assistance.<\/p>\n<p>HFS<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge an anonymous researcher for their assistance.<\/p>\n<p>iCloud<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge 3ndy1(@_3ndy1) and moyu for their assistance.<\/p>\n<p>iCloud Photo Library<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge an anonymous researcher for their assistance.<\/p>\n<p>ImageIO<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Muhamad Syaiful, an anonymous researcher, songbird for their assistance.<\/p>\n<p>IOMobileFrameBuffer<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Iain Harkiss, Jian Lee (@speedyfriend433) for their assistance.<\/p>\n<p>IOSurface<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge N.M.Praveen Nawarathne (@zblockrat), \u0e18\u0e19\u0e01\u0e24\u0e15 \u0e17\u0e31\u0e2c\u0e2b\u0e30 for their assistance.<\/p>\n<p>IOSurfaceAccelerator<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Chanwit Muenprakoddee (ChemIndy), Franco Belman at Blackwing Intelligence, Iain Harkiss, an anonymous researcher, beist, hxr1 for their assistance.<\/p>\n<p>Kernel<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Cem Onat Karagun, DARKNAVY (@DarkNavyOrg), James Duffy (@0x4A616D657344), Kang Sangkwun, Lyutoon, N.M.Praveen Nawarathne (@zblockrat), Nebula Security (@nebusecurity), Nicolas Seriot, Peter Malone, Redon Gashi of Sentry, Robert Tran, Tristan Madani (@TristanInSec) from Talence Security, Xiang Li from AOSP Lab @Nankai University, an anonymous researcher for their assistance.<\/p>\n<p>LaunchServices<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Rosyna Keller of Totally Not Malicious Software (paradisefacade.com) for their assistance.<\/p>\n<p>mDNSResponder<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Anton Pakhunov, Franciszek Kalinowski (striga.ai \/ isec.pl), Hannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast and Daniel Gruss of Graz University of Technology, and Johanna Ullrich of the Interdisciplinary Transformation University (IT:U), Issa Sancho, Jian Zhou, \u7ae0\u9c7c\u54e5@aipy (aipyaipy.com\uff09 for their assistance.<\/p>\n<p>Messages<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Pratyush Dutta for their assistance.<\/p>\n<p>Notes<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Peter Henri for their assistance.<\/p>\n<p>Notifications<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India, Himanshu Bharti @Xpl0itme From Khatima, Jan Rokita (rokita.me) for their assistance.<\/p>\n<p>PaperKit<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Rahul Raj for their assistance.<\/p>\n<p>Passwords<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Catalin Lita of Moralis, Christian Kohlsch\u00fctter, David Coomber of Info-Sec.CA, Lukasz Tulikowski at Software Cloud, Sujay Amin, an anonymous researcher for their assistance.<\/p>\n<p>ppp<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Cem Onat Karagun for their assistance.<\/p>\n<p>Printing<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Stuart Wallace for their assistance.<\/p>\n<p>Pro Res<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Meta Red Team X \u2013 Nik Tsytsarkin for their assistance.<\/p>\n<p>Quick Look<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Peter Malone for their assistance.<\/p>\n<p>RemoteServiceDiscovery<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Tristan Madani (@TristanInSec) from Talence Security, an anonymous researcher for their assistance.<\/p>\n<p>Safari<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Dem0ns @\u5929\u5e9c\u7b80\u6613\u4fe1\u5de5\u4f5c\u5ba4 for their assistance.<\/p>\n<p>Safari Downloads<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Barath Stalin K (linkedin.com\/in\/barathstalin), Exell Nakano, Manojkumar Jaganathan (linkedin.com\/in\/manojkumar-j-7ba35b202\/) with HackerBro Technologies, Praditya Fajar Ramadhan, Zhiyang Zeng (@Wester), shobhit srivastav for their assistance.<\/p>\n<p>Safari Extensions<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Jake Derouin (jakederouin.com) for their assistance.<\/p>\n<p>Sandbox Profiles<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Lachlan Bauerochse for their assistance.<\/p>\n<p>Security<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge John Lussier, Masahiro Kawada (@kawakatz), Roman Zabicki for their assistance.<\/p>\n<p>Settings<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge an anonymous researcher for their assistance.<\/p>\n<p>Share Sheet<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Atul Kishor Jaiswal, Benjamin Hornbeck for their assistance.<\/p>\n<p>Shortcuts<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Csaba Fitzl (@theevilbit) of Iru, GP, Owen Pawling (@owenpawling) for their assistance.<\/p>\n<p>Status Bar<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Andr.Ess, Rosyna Keller of Totally Not Malicious Software for their assistance.<\/p>\n<p>Terminal<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Stuart Thomas for their assistance.<\/p>\n<p>UIKit<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Jorge Welch for their assistance.<\/p>\n<p>Virtualization<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Ye Zhang (@VAR10CK) of Baidu Security for their assistance.<\/p>\n<p>VoiceOver<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Hariji Vivek Pandey for their assistance.<\/p>\n<p>WebKit<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge @TristanInSec, Behzad Najjarpour Jabbari (@_G4ru_), Big Bear, Eddy Tsalolikhin, Henock Habte, Kenneth Hsu, Maher Azzouzi, Meridian Miftari, OpenAI Codex Security \u2013 Amy Burnett, Souta Sugiyama, Vitaly Simonovich, an anonymous researcher, hamayanhamayan, lattice, ret2happy, wwwlk for their assistance.<\/p>\n<p>WebKit Canvas<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Utkarsh Pal for their assistance.<\/p>\n<p>WebKit JavaScript Bindings<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge hamayanhamayan for their assistance.<\/p>\n<p>Wi-Fi<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge E Vestavik (@Dynasty) for their assistance.<\/p>\n<p>Widgets<\/p>\n<p class=\"wp-block-paragraph\">We would like to acknowledge Vishnu Prasad P G &amp; Akshaya S, an anonymous researcher for their assistance.<\/p>\n<p>Additionally, Apple released the <a href=\"https:\/\/support.apple.com\/en-us\/149041\" rel=\"nofollow noopener\" target=\"_blank\">security content for iOS 26.7 and iPadOS 26.7<\/a>, including fixes for several vulnerabilities not listed in the security notes for iOS 27 and iPadOS 27. These include flaws in ImageIO, the kernel, IOGPUFamily, CoreMedia Video Toolbox, and WebKit that could lead to memory corruption, unexpected system or app termination, and other issues.<\/p>\n","protected":false},"excerpt":{"rendered":"Between the official release of its 2027 operating system updates, point updates to previous operating systems, and standalone&hellip;\n","protected":false},"author":2,"featured_media":848452,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[41],"tags":[165,74],"class_list":["post-848451","post","type-post","status-publish","format-standard","has-post-thumbnail","category-mobile","tag-mobile","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/848451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=848451"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/848451\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/848452"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=848451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=848451"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=848451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}