At a Glance
- iOS 26.6.1 patches 29 security issues, 21 of them in WebKit.
- The update covers iPhone 11 and later, plus the second and third generation iPhone SE.
- One fix, CVE-2026-65346 in ImageIO, could let a malicious image trigger arbitrary code execution.
- Older iPhones (XS, XS Max, XR) get iOS 18.7.10 with more than 120 fixes instead.
- Apple has not said any of the flaws have been exploited; no confirmed exploitation has been reported.
Main Story
The update is purely security. Unlike major iOS releases, iOS 26.6.1 adds no features and fixes no reported bugs; its entire purpose is closing vulnerabilities. Apple published the details in a support document, and the release spans iPhone, iPad, and Mac, where macOS Tahoe 26.6.2 addresses many of the same flaws.
Most of the attention sits on WebKit, which handles web pages in Safari, embedded browser views, email previews, and other content loaded from the internet. A flaw there can reach far beyond someone actively browsing, which is why 21 of the 29 fixes, about 72 percent, target it. Apple says several of the WebKit issues could allow maliciously crafted web content to crash Safari or corrupt memory.
Beyond WebKit, the update reaches deeper into the system. It patches three kernel vulnerabilities: one that could let a remote attacker cause an unexpected system termination, another that could let an app read kernel memory or crash the system, and a third tied to kernel memory corruption. An audio component flaw could leak sensitive user information, and a telephony issue could let an attacker in a privileged network position bypass authentication and intercept traffic.
What's Inside iOS 26.6.1, by Component
Component
What It Does
What the Fix Addresses
WebKit (21 fixes)
Engine behind Safari and in-app browsers
Malicious web content could crash Safari or corrupt memory
Kernel (3 fixes)
Core of the operating system
Unexpected system termination; reading or corrupting kernel memory
ImageIO
Framework that decodes images
CVE-2026-65346: a crafted image could allow arbitrary code execution
Audio
Sound and voice processing
A flaw that could leak sensitive user information
Telephony
Cellular and network handling
A flaw that could bypass authentication and intercept network traffic
WebKit (21 fixes)
FunctionEngine behind Safari and in-app browsers
FixPrevents Safari crashes & memory corruption
Kernel (3 fixes)
FunctionCore of the operating system
FixFixes unexpected termination & memory read/corruption
ImageIO
FunctionFramework that decodes images
FixCVE-2026-65346: blocks arbitrary code execution
Audio
FunctionSound and voice processing
FixPatches sensitive user info leak
Telephony
FunctionCellular and network handling
FixBlocks auth bypass & traffic interception
| Component | What It Does | What the Fix Addresses |
|---|---|---|
| WebKit (21 fixes) | Engine behind Safari and in-app browsers | Malicious web content could crash Safari or corrupt memory |
| Kernel (3 fixes) | Core of the operating system | Unexpected system termination; reading or corrupting kernel memory |
| ImageIO | Framework that decodes images | CVE-2026-65346: a crafted image could allow arbitrary code execution |
| Audio | Sound and voice processing | A flaw that could leak sensitive user information |
| Telephony | Cellular and network handling | A flaw that could bypass authentication and intercept network traffic |
The Standout Fix: A Malicious Image Flaw
The release's most serious patch, according to security professionals, is CVE-2026-65346, an integer overflow in ImageIO, the framework that decodes images across iPhone, iPad, and Mac. Adam Boynton, a senior enterprise strategy manager at Jamf, an Apple device management vendor, called it the standout fix in the update, because exploiting the image-processing flaw could let an attacker write memory where they should not and gain code execution.
Apple's own description says processing a maliciously crafted image could lead to arbitrary code execution. Neither Apple nor the Indian computer emergency response agency CERT-In, which rated the advisory critical, has reported active exploitation of any of the 29 flaws. But a vulnerability capable of arbitrary code execution is treated as serious even without proof of attacks.
One detail in the release notes points to a shift in how these bugs are being found. Nine of the WebKit fixes are credited to OpenAI Codex Security, an AI-assisted vulnerability discovery effort, sometimes alongside independent researchers. That pattern matches what Reuters reported in July: Apple is pushing software updates earlier than in previous cycles in response to AI-driven security concerns.
Status Table: Confirmed, Reported, Unknown
Status
Claim
Confirmed (Apple)
29 fixes; 21 in WebKit; CVE-2026-65346 allows arbitrary code execution via a crafted image
Reported (Third Party)
120+ fixes in iOS 18.7.10 (Forbes' count); 704MB and roughly 15-minute install (Forbes' testing); CERT-In's "critical" rating
Unknown
Whether any flaw was exploited before the patch; the iOS 27 release date; why Apple shipped out of cycle
Confirmed (Apple)
Status
Confirmed
Claim
29 fixes; 21 in WebKit; CVE-2026-65346 allows arbitrary code execution via a crafted image
Reported (Third Party)
Status
Reported
Claim
120+ fixes in iOS 18.7.10 (Forbes' count); 704MB & ~15-min install; CERT-In "critical" rating
Unknown
Status
Unknown
Claim
Whether flaw was exploited prior; iOS 27 release date; reason for out-of-cycle release
| Status | Claim |
|---|---|
| Confirmed (Apple) | 29 fixes; 21 in WebKit; CVE-2026-65346 allows arbitrary code execution via a crafted image |
| Reported (Third Party) | 120+ fixes in iOS 18.7.10 (Forbes' count); 704MB and roughly 15-minute install (Forbes' testing); CERT-In's "critical" rating |
| Unknown | Whether any flaw was exploited before the patch; the iOS 27 release date; why Apple shipped out of cycle |
Which Update Does Your iPhone Get?
Your iPhone
Update to Install
What It Includes
iPhone 11 and later (2019 onward)
iOS 26.6.1
29 security fixes
iPhone SE, 2nd and 3rd generation
iOS 26.6.1
29 security fixes
iPhone XS, XS Max, XR (2018)
iOS 18.7.10
More than 120 fixes
iPhone 11 & Later (2019 onward)
Update
iOS 26.6.1
Includes
29 security fixes
iPhone SE (2nd & 3rd Gen)
Update
iOS 26.6.1
Includes
29 security fixes
iPhone XS, XS Max, XR (2018)
Update
iOS 18.7.10
Includes
More than 120 fixes
| Your iPhone | Update to Install | What It Includes |
|---|---|---|
| iPhone 11 and later (2019 onward) | iOS 26.6.1 | 29 security fixes |
| iPhone SE, 2nd and 3rd generation | iOS 26.6.1 | 29 security fixes |
| iPhone XS, XS Max, XR (2018) | iOS 18.7.10 | More than 120 fixes |
On iPad, iOS 26.6.1's equivalent, iPadOS 26.6.1, covers iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later, according to Apple's security advisory.
For the three iPhones that can run iOS 18 but not iOS 26, the iPhone XS, iPhone XS Max, and iPhone XR, Apple released iOS 18.7.10 at the same time. That update is far larger, with more than 120 issues addressed by Forbes' count, covering a wider range of components. All three phones date to September 2018, nearly eight years old, and Apple is still shipping security fixes for them.
Should You Update Now, or Wait for iOS 27?
A reasonable question is whether to bother with iOS 26.6.1 when iOS 27 is expected in September. Apple has not confirmed a release date. The answer from security experts is to update now.
Jake Moore, global cybersecurity advisor at ESET, told Forbes that WebKit and kernel flaws are the most important to patch, because WebKit vulnerabilities can be triggered through malicious web content the user cannot control. And since the details are now public, staying on an older version offers little practical benefit when a patch is available.
The Pace of Apple's Security Updates
Release
Timing
Scope
iOS 26.6
Late July 2026
About 90 vulnerabilities
iOS 26.6.1
August 17, 2026
29 vulnerabilities
iOS 18.7.10
August 17, 2026
More than 120 vulnerabilities, older devices only
iOS 26.6
Timing
Late July 2026
Scope
About 90 vulnerabilities
iOS 26.6.1
Timing
August 17, 2026
Scope
29 vulnerabilities
iOS 18.7.10
Timing
August 17, 2026
Scope
More than 120 vulnerabilities (older devices)
| Release | Timing | Scope |
|---|---|---|
| iOS 26.6 | Late July 2026 | About 90 vulnerabilities |
| iOS 26.6.1 | August 17, 2026 | 29 vulnerabilities |
| iOS 18.7.10 | August 17, 2026 | More than 120 vulnerabilities, older devices only |
How to Install
Open Settings, tap General, then Software Update, and choose Download and Install. The download is small, roughly 704MB on an iPhone 17 Pro Max in Forbes' testing, and installation finished in about 15 minutes on that device. Phones on older iOS versions will download a larger file.
A backup is sensible first, and keeping Automatic Updates turned on means fixes like this one arrive without requiring a manual check.
If you cannot update immediately, Apple's Lockdown Mode provides extra protection for people who may be targeted by sophisticated attacks, and the usual precautions apply: avoid opening links, attachments, or images from unknown senders until you have installed the patch.
FAQ
Editorial Note
PetaTech24 has not independently tested this update. Install size and time figures come from Forbes' testing and may vary by device. Please verify your device's software version in Settings before updating.
Sources / Attribution
- Apple security support document for iOS 26.6.1 and iPadOS 26.6.1 (primary source for the vulnerability list, component breakdown, and supported devices).
- Forbes, August 20, 2026 (David Phelan), the original report on the 29 fixes and the iOS 18.7.10 device split, including the 704MB and 15-minute install figures.
- Forbes, August 19, 2026 (Kate O'Flaherty), including statements from ESET's Jake Moore and Jamf's Adam Boynton.
- Reuters, July 2026, on Apple pushing software updates earlier than in previous cycles in response to AI-driven security concerns.
- ZDNET (August 18, 2026), corroborating the 29-flaw count and the absence of reported exploitation.
- AppleMagazine (August 18, 2026), corroborating the WebKit, kernel, and ImageIO details and the OpenAI Codex Security credits.
- eSecurityPlanet and the CERT-In advisory (August 19, 2026), corroborating the CVE-2026-65346 severity and the "critical" rating.
.png)
0 Comments