Vulnerabilities

Apple Patches Major Security Flaws With iOS 18 Refresh

Apple warns that attackers can use Siri to access sensitive user data, control nearby devices, or view recent photos without authentication. 

iPhone security

Apple’s long-awaited iOS 18 refresh landed Monday with fixes for at least 33 security vulnerabilities that expose iPhones and iPads to an assortment of malicious hacker attacks.

According to a bulletin from Cupertino, iOS 18 has been fitted with fixes for vulnerabilities in core components including accessibility features, Bluetooth, Control Center, and Wi-Fi, with several flaws allowing unauthorized access to sensitive data or full device control.

The company called attention to several problems in the Accessibility component that allow attackers with physical access to devices to use Siri to access sensitive user data, control nearby devices, or view recent photos without authentication. 

Apple also documented a serious bug in the Control Center that could be exploited to allow a mobile app to record the screen without displaying an indicator.

The iOS 18 rollout also fixes a Core Bluetooth flaw that allows a malicious Bluetooth input device to bypass device pairing; a kernel vulnerability that leaks network traffic outside a VPN tunnel; a WiFi bug that allows an attacker to force a device to disconnect from a secure network; and a multiple Safari Private Browsing and sandbox bypasses.

The company did not mark any of the iOS 18 vulnerabilities in the already-exploited category.  

Advertisement. Scroll to continue reading.

Apple also pushed out macOS Sequoia 15 with a massive batch of patches for security defects across various components of the operating system. 

The company documented multiple critical macOS vulnerabilities that could allow unauthorized access to sensitive user data, privilege escalation, system modification, and unexpected application crashes.

Related: Apple Suddenly Drops NSO Group Spyware Lawsuit

Related: Apple Blunts Zero-Day Attacks With iOS 17.4 Update

Related: Apple Ships iOS 17.3, Warns of WebKit Zero-Day Exploitation

Related: Apple Ships iOS 17.2 With Urgent Security Patches

Related Content

Endpoint Security

Apple announced that dozens of vulnerabilities have been patched in each of its operating systems.

Vulnerabilities

The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.

Endpoint Security

A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities.

Mobile & Wireless

The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers.

Application Security

The company blocked over 1.1 billion accounts and $2.2 billion in potentially fraudulent transactions.

Mobile & Wireless

The tech giant has also ported the patch for a recent deleted chats recovery issue to older versions of iOS.

Data Protection

Apple rolled out the security patches for dozens of iPhone and iPad models and generations.

Malware & Threats

Masquerading as popular cryptocurrency wallets, the apps can hijack recovery phrases and private keys.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version