preloader

· digital-security apple ios macos patch-management vulnerability-management mobile-security europe enterprise

Apple Just Patched Nearly 90 iPhone Flaws in One Update, Several of Them Handing Over the Kernel

Source: 9to5mac

Apple released iOS 26.6 and iPadOS 26.6 on July 27, alongside macOS Tahoe 26.6, closing out one of its larger security updates of the year. The iOS and iPadOS advisory lists 78 individual entries covering 87 CVEs, spanning the kernel, WebKit, IOKit, SceneKit, Game Center, CloudAttestation, and ImageIO. The macOS advisory is larger still, at well over 130 fixes. Apple’s own language is measured, it does not say any of these were exploited in the wild before the patch, but a large batch of kernel and sandbox-escape fixes shipping together is exactly the kind of release that gets reverse-engineered into working exploits within days.

The kernel is where the real damage lives

The single most serious issue is CVE-2026-64747, a buffer overflow in AVEVideoEncoder that lets a malicious application execute arbitrary code with kernel privileges, the highest level of access a bug on an iPhone can reach. It sits alongside more than a dozen other kernel entries covering use-after-free conditions, out-of-bounds reads and writes, and race conditions, plus an IOKit race condition and sandbox-escape flaws in Game Center and libc that would let an app step outside the boundaries iOS is supposed to enforce around it. WebKit picked up its usual share too: memory disclosure bugs, UI spoofing issues, and a flaw letting a website read files it should never see. None of this requires a sophisticated nation-state actor to weaponise. It requires someone with the patched and unpatched binaries side by side, which is public information the moment Apple ships the fix.

For a managed fleet, “update your phone” is the easy 5 percent

The advice to individual users is simple: install the update. The advice for any business running iPhones and Macs as part of its infrastructure, whether that is a sales team’s devices, a hospital’s clinical tablets, or engineers’ MacBooks with production access, is considerably harder to execute well. It means confirming your MDM policy actually enforces the update rather than just recommending it, checking whether any devices are pinned to an older OS version for compatibility reasons that now carry a kernel-level cost, and having a documented compliance record you can show a regulator or auditor if one of those unpatched devices is later involved in an incident. Under GDPR and NIS2, “we hadn’t gotten around to it yet” is not a defensible position once a fix has been public for weeks.

If your organisation needs a mobile device management policy that actually closes these windows, or a vulnerability management process that turns an Apple advisory into a tracked, auditable rollout across every device that touches your data, contact Excello Digital. We help European businesses turn patch Tuesdays, and patch Mondays, into routine operations instead of fire drills.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!