Skip to content
LIVE

Apple Fixes Nearly 30 Security Flaws in iOS, iPadOS and macOS — Here's Why to Update Now

Apple's August 17 updates patch close to 30 vulnerabilities, most in the Safari engine WebKit. None were exploited before the fix, but that changes once patches are public.

Meridians Money Desk

Published 21 August 2026 · Updated 21 August 2026 · 4 min read

Apple Fixes Nearly 30 Security Flaws in iOS, iPadOS and macOS — Here's Why to Update NowSoftware
Photo: Photo by Jakub Zerdzicki / Pexels (Pexels License — free to use, no attribution legally required (credited above as good practice).)

The short answer

  • Apple released iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 on August 17, 2026, fixing 29 documented vulnerabilities, 21 of them in WebKit, the engine behind Safari.
  • Apple says none of the flaws were known to be exploited before the release, but public patches let researchers reverse-engineer what was fixed — which is why security specialists recommend updating promptly.
  • One flaw could let a malicious app leak sensitive user data; a separate telephony bug could let an attacker bypass IPSec authentication to intercept network traffic.
  • Nine of the credited vulnerabilities came from a source called "OpenAI Codex Security," one of the first public credits of that kind on an Apple advisory.

Apple released iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 on August 17, 2026, closing out close to 30 documented security vulnerabilities. Most are in WebKit, the engine that powers Safari and any app that renders web content. Apple's advisory says none of the flaws are known to have been exploited before the patch — but that window closes once a fix is public, since researchers and attackers alike can compare old and new code to find what changed.

What's covered

The same week, Apple also shipped macOS Tahoe 26.6.2, iOS 18.7.10 and iPadOS 18.7.10 for older devices still on the iOS 18 track, and Safari 26.6.1 for Macs running macOS Sonoma and macOS Sequoia. Apple's security-content page lists documented CVEs including CVE-2026-65339, CVE-2026-65347, CVE-2026-65346, CVE-2026-64788, CVE-2026-65343 and CVE-2026-65329, along with multiple WebKit CVEs such as CVE-2026-64784 and CVE-2026-64715.

What the flaws could do

  • 21 of the 29 documented CVEs are in WebKit, the browser engine behind Safari and in-app web views
  • One flaw could let a malicious app leak sensitive user data
  • A separate telephony bug could let an attacker bypass IPSec authentication to intercept network traffic
  • Additional fixes touch audio, image-processing and kernel components

Who's covered by the update

iOS 26.6.1 and iPadOS 26.6.1 cover iPhone 11 and later, and a range of iPad Pro, Air and mini models dating back to roughly 2019. Devices too old for iOS 26 get the equivalent fixes through iOS 18.7.10 and iPadOS 18.7.10.

An unusual credit line

Nine of the vulnerabilities in this release are credited to "OpenAI Codex Security" in Apple's advisory — a detail that stands out because it appears to be one of the first times Apple has publicly credited an AI-assisted security research effort by name. This is also Apple's third security release in three weeks, a pace that outside researchers have linked to AI tools surfacing bugs faster than Apple's normal release cadence.

Sources

Every factual claim above is traceable to these documents. Check them — that is why they are here.

About this byline

Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.

Sponsored

Paid placement · not editorial

Related reading

The Meridians Brief

One considered email a week

What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.

Sign-up opens with our launch issue. Nothing is sent or stored yet.