[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0sL5iIvHwbGrn5UEmOrgZmA90VJYFeKg5AiieIagR_8":3},{"article":4,"iocs":39},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"887bb3c7-4cbd-4221-9bac-5472c469c110","Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe","apple-patches-87-vulnerabilities-in-ios-155-in-macos-tahoe-6a34ce","Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek.","Apple has released significant security updates, patching 87 vulnerabilities in iOS and iPadOS, and 155 in macOS Tahoe. These fixes address issues ranging from arbitrary code execution and data access to DoS conditions and privilege escalation. Similar updates were also rolled out for macOS Sequoia and Sonoma, with many vulnerabilities affecting multiple platforms. While the advisories do not mention active exploitation in the wild, the sheer volume of patched flaws highlights ongoing security challenges.","Apple patches 87 vulnerabilities in iOS and 155 in macOS Tahoe.","Apple announced on Monday that it has released patches for dozens of vulnerabilities discovered recently in its operating systems. The company patched 87 vulnerabilities with the release of iOS 26.6 and iPadOS 26.6. The flaws can be exploited to access sensitive user data, fingerprint users, cause a DoS condition, execute arbitrary code, delete files, modify the file system, bypass security, add contacts without authorization, spoof the UI, and escalate privileges. In macOS Tahoe 26.6, Apple fixed 155 vulnerabilities, including ones allowing access to sensitive user data, arbitrary code execution, security bypasses, and DoS attacks. macOS Sequoia 15.7.8 includes fixes for 138 security holes, while macOS Sonoma 14.8.8 resolves 127 issues. Many of the vulnerabilities were patched across all of these platforms. Advertisement. Scroll to continue reading. “The one worth a second look is CVE-2026-43810, where Apple notes a remote user may be able to corrupt kernel memory, because remote changes the economics of an attack chain considerably,” commented Adam Boynton, senior enterprise strategy manager at Jamf. Roughly 100 flaws have been patched by Apple in each of its other operating systems: watchOS, tvOS, and visionOS. The latest Safari update fixes nearly a dozen vulnerabilities, including ones that can be exploited to access sensitive user data or crash the browser. The advisories do not mention in-the-wild exploitation. Additional details are available in Apple’s security advisories. Related: Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari Related: New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones Related: Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Origin Energy Data Breach Affects 900,000 AustraliansNvidia and Tech Giants Launch AI Security AllianceCoca-Cola Confirms Data Breach After Fairlife Ransomware AttackAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on ExploitsMCBS Data Breach Affects 1.2 Million IndividualsRockwell Patches Code Execution Flaws in Arena Simulation SoftwareData Breach Confirmed After Australian Energy Giant Origin Is HackedChick-fil-A Accounts Get Fried in Credential Stuffing Attack Latest News Cyera Acquiring Oasis Security in $1 Billion DealOT Security Startup Frenos Raises $1.52 MillionMicrosoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Act Security Emerges from Stealth to Fight the Patch ProblemHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack BlockerHush Security Raises $30 Million for AI Agent GovernanceGoogle Adopts New Threat Actor Naming SystemUnpatched Fastjson Vulnerability Exploited in Attacks Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveBarry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fapple-patches-87-vulnerabilities-in-ios-155-in-macos-tahoe\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F09\u002FApple-MacBook-iPhone.jpeg","2026-07-28T14:19:31+00:00","2026-07-28T16:00:19.753565+00:00",8,[18,21,23,25,27,29],{"name":19,"type":20},"iOS","product",{"name":22,"type":20},"iPadOS",{"name":24,"type":20},"macOS Tahoe",{"name":26,"type":20},"macOS Sequoia",{"name":28,"type":20},"macOS Sonoma",{"name":30,"type":20},"Safari","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":31,"icon":33,"name":34,"slug":35},null,"Vulnerabilities","vulnerabilities",[37],{"category":38},{"id":31,"icon":33,"name":34,"slug":35},[40],{"type":41,"value":42,"context":43},"cve","CVE-2026-43810","Vulnerability allowing remote user to corrupt kernel memory"]