Apple has addressed shut to twenty vulnerabilities within the open supply WebKit browser engine that underpins its Safari browser, that are current in its desktop and pocket book, and cellular working techniques.
The updates, which take Safari to model 26.6.1 in macOS Sonoma and macOS Sequoia, macOS Tahoe to model 26.6.2, and iOS and iPad OS to variations 18.7.10 and 26.6.1 respectively, had been all launched over the previous couple of days.
In widespread with most different software program suppliers, the updates mark a major uptick within the quantity of points contained in Apple’s safety fixes, and in keeping with Cupertino, 9 of them are attributed to a researcher utilizing OpenAI Codex Security – a analysis preview that connects to GitHub to assist groups establish coding flaws – a transparent demonstration of how synthetic intelligence (AI) is upending the world of vulnerability discovery.
Left alone, the problems could result in a number of disagreeable outcomes, together with browser and course of termination, reminiscence corruption, and crashes. In a single occasion, a flaw tracked as CVE-2026-64778 in WebKit Historical past could trigger a person lured to a maliciously crafted web site to inadvertently leak delicate information.
As is customary, Apple remained largely tight-lipped about whether or not or not any of the issues have been exploited within the wild, however WebKit flaws are sometimes highly-favoured by risk actors, as Adam Boynton, senior enterprise technique supervisor at Jamf, defined.
“[WebKit is] one of many largest assault surfaces on the [Apple] platform. Reminiscence corruption doesn’t imply distant code execution, however these have develop into browser exploit chains up to now,” he defined.
Nevertheless, added Boynton, the quantity of WebKit flaws within the newest replace will not be probably the most noteworthy factor about it – the standout repair in his view is CVE-2026-65346, an integer overflow in ImageIO, a framework that permits purposes to learn and write picture recordsdata.
“Exploiting it might permit an attacker to put in writing reminiscence the place they shouldn’t and acquire code execution. Picture parsing flaws have traditionally been the supply mechanism for zero-click adware focusing on executives and different high-value people,” stated Boynton.
Additionally price immediate consideration is CVE-2026-65329, a telephony problem affecting iPhones which might allow an attacker with community privileges to bypass IPSec authentication and eavesdrop on community site visitors.
Kev catalogue
In the meantime, the US Cybersecurity and Infrastructure Safety Company (Cisa) has added one other Apple flaw – CVE-2026-65400 – to its Known Exploited Vulnerabilities (Kev) catalogue of points deemed of great threat to the federal authorities.
CVE-2026-65400 was addressed by Apple earlier this month. It’s one other improper authentication vulnerability that might permit a risk actor with a longtime presence on the goal community to authenticate to the goal gadget’s Display Sharing function with out legitimate credentials,.
In response to the Dutch Nationwide Cyber Safety Centre – NCSC-NL – it has been used in opposition to a number of techniques upon which port 5900 was uncovered to the general public web to acquire root entry and set up a Monero crypto miner.
As CVE-2026-65400 allows root entry, a risk actor might additionally use it as a part of a wider assault to determine persistence, steal credentials and information, and deploy different malware, though on the time of writing there seems to be no indication that it has been utilized in any ransomware assaults.
Below an inside directive, US authorities businesses are obligated to remediate CVE-2026-65400 by Friday 21 August – its inclusion on the commonly up to date Kev checklist is a sign that personal sector CISOs must also take steps to remediate it in the event that they haven’t already.