Apple released iOS 26.6.1 and iOS 18.7.10, patching dozens of security flaws including nearly 20 WebKit bugs and several Kernel vulnerabilities in the newer release, and more than 30 WebKit and a dozen Kernel issues in the older one. Security researchers flagged a standout ImageIO flaw, CVE-2026-65346, that could allow arbitrary code execution simply from a malicious image, the kind of zero-click bug historically used to deliver spyware to high-value targets.
Another fixed flaw in Telephony could let an attacker in a privileged network position bypass IPSec authentication and intercept traffic. Apple, true to form, offers minimal detail about what exactly these bugs did, citing a desire to give users time to update before attackers can reverse-engineer the fixes — though it also declines to say whether any were already being exploited.
The updates follow Apple's warning that spyware is targeting iPhone users in 110 countries and arrive weeks after iOS 26.6 patched 90 separate issues. macOS Tahoe also received a matching patch for several of the same flaws.
The full dispatch is available from the source below.