Marrakech – Morocco’s Directorate Basic of Info Methods Safety (DGSSI) issued a safety bulletin on Tuesday warning of essential vulnerabilities affecting a number of Apple merchandise.
The advisory came from the company’s cyberattack monitoring and response middle, which operates underneath the Nationwide Protection Administration, and it rated each the danger and the affect as essential.
The bulletin covers iOS and iPadOS variations earlier than 26.6.1 and 18.7.10, together with macOS Tahoe variations earlier than 26.6.2. It warns that attackers may exploit the failings to run code remotely, attain confidential information, elevate their privileges, or bypass safety measures.
The DGSSI additionally flagged one vulnerability, tracked as CVE-2026-3783, as liable to energetic exploitation.
The Moroccan warning adopted Apple’s launch of iOS 26.6.1 on August 17, an replace that patched 29 safety vulnerabilities. The identical spherical of fixes reached iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 26.6.1. Apple additionally issued iOS 18.7.10 and iPadOS 18.7.10 for older gadgets unable to run its newest methods.
A lot of the vulnerabilities concerned WebKit, the browser engine behind Safari, the place 21 flaws have been mounted. 9 have been credited to OpenAI’s Codex Safety group. The remaining fixes addressed an ImageIO flaw that would permit arbitrary code execution via crafted pictures, an audio bug that would leak delicate info, and three kernel vulnerabilities.
On iOS, Apple additionally corrected a telephony flaw that permit an attacker on the identical community bypass IPSec authentication and intercept visitors.
The discharge marked Apple’s third safety replace in three weeks. It arrived 11 days after an emergency macOS repair for a separate Display screen Sharing flaw, and weeks earlier than the anticipated launch of iOS 27. The Monetary Occasions reported earlier this month that AI instruments are uncovering vulnerabilities sooner than Apple’s standard replace cycle can deal with them.
Apple, for its half, reported that not one of the disclosed vulnerabilities had been confirmed as actively exploited. Customers can set up the updates via Settings, then Basic, then Software program Replace.
Learn additionally: Morocco Ranks 43rd Globally in National Cyber Security Index