Apple patches dozens of WebKit bugs in macOS, iOS updates

Apple released macOS Tahoe 26.6.2 and iOS/iPadOS 26.6.1 to fix dozens of WebKit vulnerabilities; macOS update addresses 21 WebKit flaws within a 28-defect security patch.
Apple on Monday released macOS Tahoe 26.6.2 and iOS and iPadOS 26.6.1 updates that fix dozens of vulnerabilities, most affecting the WebKit browser engine. The macOS package covers 28 security defects, including 21 WebKit flaws that could cause Safari or other processes to crash, trigger memory corruption or expose sensitive data. iOS 26.6.1 and iPadOS 26.6.1 include the same 28 fixes and add a patch for an authentication issue in Telephony that could allow an attacker to bypass IPSec authentication and intercept network traffic.
Apple also published iOS 18.7.10 and iPadOS 18.7.10 for older device lines. Those releases correct more than 120 bugs, including over 40 issues in WebKit.
The WebKit fixes address risks such as sandbox escapes and cross-origin data exfiltration that can be chained from web content. WebKit is the rendering and JavaScript engine used by Safari and by other apps that display web content on Apple platforms, so flaws in it commonly affect any app that embeds the engine.
Beyond WebKit, the updates resolve multiple kernel vulnerabilities that could corrupt or expose kernel memory, crash systems, bypass network filters or allow unauthorized access to user data. Additional patches cover components including Audio, ImageIO, IOGPUFamily, Accessibility, AirDrop, App Store, CoreAudio, CoreMedia, Foundation, Maps, Siri and WebRTC.
Apple’s security notes do not indicate any of the patched vulnerabilities were actively exploited. The company recommends users install the updates promptly. Full technical details, including CVE identifiers and advisories, are available on Apple’s security updates page.








