Endpoint Security

iOS, macOS 26.4 Roll Out With Fresh Security Patches

Apple released security fixes for older devices as well, in iOS 18.7.7, iPadOS 18.7.7, macOS Sequoia 15.7.5, and macOS Sonoma 14.8.5.

Apple patches

Apple on Tuesday rolled out a fresh wave of security updates to resolve more than 80 vulnerabilities across its mobile and desktop operating systems.

iOS 26.4 and iPadOS 26.4 were released for the latest generation iPhone and iPad devices with patches for nearly 40 security defects.

WebKit received fixes for eight bugs that could be exploited by malicious websites to bypass policy enforcement, mount XSS attacks, fingerprint users, escape the sandbox, or crash the process.

Issues addressed in the kernel could be exploited to disclose kernel memory, leak sensitive kernel state, corrupt kernel memory, or write kernel memory.

Vulnerabilities resolved in other components may lead to network traffic interception, access to biometrics-gated Protected Apps, process crashes, app termination, denial-of-service (DoS), installed apps enumeration, sandbox escape, and access to sensitive information.

Patches for roughly two dozen of these security defects were delivered to users of older devices as part of the iOS 18.7.7 and iPadOS 18.7.7 security updates.

Advertisement. Scroll to continue reading.

On Tuesday, Apple also rolled out macOS Tahoe 26.4 with fixes for over 75 bugs, including roughly 30 flaws that were addressed with the iOS 26.4 and iPadOS 26.4 updates.

The patches target issues in dozens of native components, but also vulnerabilities in third-party open source dependencies, including multiple Apache libraries, Curl, and LibPNG.

Additionally, Apple released macOS Sequoia 15.7.5 and macOS Sonoma 14.8.5 with patches for over 50 of these vulnerabilities each.

While tvOS 26.4 and watchOS 26.4 were rolled out with fixes for over a dozen vulnerabilities each, visionOS 26.4 is bringing patches for nearly 30 bugs to its users.

On Tuesday, Apple also announced the release of Safari 26.4 with fixes for the eight WebKit bugs. Xcode 26.4 was rolled out with patches for two flaws.

Apple makes no mention of any of these security defects being exploited in the wild. Additional information on the updates can be found on the company’s security advisories page.

Related: Apple Debuts Background Security Improvements With Fresh WebKit Patches

Related: Apple Updates Legacy iOS Versions to Patch Coruna Exploits

Related: Apple iPhone and iPad Cleared for Classified NATO Use

Related: Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’

Related Content

Vulnerabilities

The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.

Vulnerabilities

The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.

Vulnerabilities

The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.

Vulnerabilities

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.

Vulnerabilities

Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges.

Government

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

Vulnerabilities

Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.

Mobile & Wireless

The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version