Apple's latest security updates patch over 120 vulnerabilities across macOS and iOS with focus on WebKit

Apple has released a comprehensive set of security patches for macOS Tahoe, iOS, and iPadOS, addressing critical vulnerabilities in WebKit and other core components, prompting users to update promptly to mitigate risks.

Apple has issued a fresh round of security updates for macOS Tahoe, iOS and iPadOS, with the bulk of the work focused on WebKit, the browser engine behind Safari and other apps that display web content. The fixes address issues that could have allowed browser crashes, memory corruption, disclosure of sensitive data, arbitrary code execution and, in some cases, unexpected system failure. According to Clubic and Apple’s security notes, the macOS Tahoe release alone closes 28 vulnerabilities, including 21 in WebKit.

On iPhone and iPad, Apple’s iOS 26.6.1 and iPadOS 26.6.1 include the same 28 fixes, plus an additional Telephony patch. Apple said a privileged attacker on the network could have bypassed IPSec authentication, the protocol used to secure VPN traffic, and intercepted network data. The company also credited OpenAI Codex Security for identifying nine of the 29 issues fixed in this release, according to the Clubic report.

Apple has also pushed iOS 18.7.10 and iPadOS 18.7.10 for older devices that cannot run iOS 26. Clubic said this branch fixes more than 120 bugs, with over 40 in WebKit. Among the risks were sandbox escapes, where an app could break out of its isolated environment, and cross-domain data exfiltration, where a malicious website could pull information from another site. Apple also patched 18 kernel issues that could lead to memory corruption or bypass network filters.

The broader picture is that Apple continues to treat WebKit as a high-value attack surface because it is embedded far beyond Safari, including in Mail, the App Store and other apps that render web content. Security write-ups from MacRumors and Apple’s own support pages show that recent releases have repeatedly carried large batches of fixes across the kernel, ImageIO, Audio and other core components, even if Apple has not said the latest flaws are under active exploitation. For users, the practical message is clear: install the updates promptly, especially on devices exposed to untrusted web content or public networks.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.