Index  ›  tech  ›  Forbes
tech · Forbes ↗

iOS 26.6—Apple Just Gave iPhone Users 90 Reasons To Update Now

Forbes Published Jul 29, 2026 Reviewed Jul 29, 2026 ✓ Reviewed by citations.press editors
iOS 26.6—Apple Just Gave iPhone Users 90 Reasons To Update Now
iOS 26.6 and iPadOS 26.6 are available for iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
6 device generations · supported device generations for iOS 26.6 and iPadOS 26.6
Anthropic’s Claude AI agent, specifically credited to Milad Nasr and Nicholas Carlini, discovered CVE-2026-64757, one of the flaws patched in iOS 26.6.
1 CVE · CVE-2026-64757 discovered by Anthropic’s Claude
Adam Boynton of Jamf reported that 19 of the iOS 26.6 patches reside in the Kernel, though most require an attacker to already have code running on the device.
19 patches · Kernel patches in iOS 26.6
CVE-2026-43810, patched in iOS 26.6, could allow a remote attacker to corrupt kernel memory, according to Apple, significantly lowering the barrier for attack chains.
1 CVE · CVE-2026-43810 in iOS 26.6

Update July 29, 2026: This article, first published on July 28, has been updated to include expert commentary about the issues fixed in iOS 26.6, including a reason to update now to the new iPhone software.

Apple has released iOS 26.6, along with a long list of nearly 90 iPhone security fixes. One of the last iPhone upgrades before iOS 27 is launched this Fall, the iOS 26.6 update is light on features, but heavy on bug fixes. The iOS 26.6 update also paves the way for some of the Siri features due to launch in iOS 27.

Apple does not provide much detail about the security fixes issued in iOS 26.6, to give iPhone users as much time as possible to update before attackers can get hold of the details.

But experts say the flaws iOS 26.6 fixes in WebKit, the engine that underpins Apple’s Safari browser, could have the greatest impact on iPhone users. Daniel Card, a cybersecurity consultant at Xservus Limited, highlights the browser based WebKit issues, which he says are more likely to be leveraged by attackers.

For example, iOS 26.6 addresses CVE-2026-64730, which could allow an attacker to perform UI spoofing, if you visit a website that frames malicious content, according to the iPhone maker’s support page.

Apple’s iOS 26.6 also patches multiple issues in the Kernel, at the heart of the iOS operating system. One of the most concerning is CVE-2026-64735, which could allow a remote attacker to bypass network filters. Meanwhile, CVE-2026-64721 could see an app be able to access sensitive user data.

Of the iOS 26.6 patches, 19 sit in the kernel, but most still require an attacker to already have code running on the device, says Adam Boynton, senior enterprise strategy manager at cybersecurity outfit Jamf.

However, he says CVE-2026-43810 deserves a “second look.”

“Apple notes a remote user may be able to corrupt kernel memory, because remote changes the economics of an attack chain considerably,” Boynton explains.

Beyond phishing, the iOS 26.6 WebKit fixes could help protect users from sophisticated attacks using spyware, according to Boynton. “The raw material for targeted spyware is browser engine memory corruption and those chains are expensive enough that they get pointed at specific people like senior executives, journalists — anyone whose access justifies the cost.”

Another serious issue fixed in iOS 26.6 is an integer overflow vulnerability in ImageIO tracked as CVE-2026-43818, where processing a maliciously crafted image may lead to arbitrary code execution. These types of flaws are often used alongside other vulnerabilities in attacks utilising spyware.

“We tend to think of photos as harmless, but in fact a phone has to process every image it receives,” says Jake Moore, global cybersecurity advisor at ESET.

Although unlikely, if there happens to be a flaw in the way the phone processes a picture, it could “become the attack,” says Moore. “Although Apple hasn’t said any of these ImageIO flaws have actually been exploited, in iOS 26.6 they are rightly patching weaknesses before they become a potential attack vector — which is exactly what you want from a security update.”

Other iOS 26.6 fixes have patched some apps which were “accessing data they shouldn’t,” says Moore. “Most people think of cyberattacks as malware, whereas actually it is often permission abuse by seemingly harmless apps.”

Interestingly, Anthropic’s Claude, an AI agent, is credited with finding one of the flaws. CVE-2026-64757 is credited to “Milad Nasr and Nicholas Carlini with Claude, Anthropic.”

Apple’s iOS 26.6 comes nearly a month after the iOS 26.5.2 update, a security only upgrade that represented a shift in Apple’s patch cycle as AI helps researchers find bugs more quickly and at scale.

Apple’s iOS 26.6 and iPadOS 26.6 are available for the iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later and iPad mini 5th generation and later.

While iOS 26.6 contains a large number of updates, Card points out that the nature of the fixes themselves are more important in any patch cycle. “The WebKit bugs are the reason users should care, as they can be leveraged by phishing kits for example,” he says.

In the case of iOS 26.6, that means updating as soon as possible. “I’d say two things to people: Make sure your phones have enough storage to update. Make sure your devices are patching — it only takes a few minutes.”

Boynton thinks the iOS 26.6 WebKit fixes, which could allow spyware to target iPhone users, are “the honest reason to update promptly, rather than eventually.”

While spyware targets certain subsets of iPhone users, once the details of patches are out there, the malware can be used more widely, according to Boynton. “Most people will never be a target worth that kind of investment. But once a vulnerability is patched and documented it stops being expensive, and it filters down to attackers who could never have afforded it in the first place.”

You know what to do. Go to Settings > General > Software Update and upgrade now to iOS 26.6 to keep your iPhone safe.

This article was originally published by Forbes ↗. citations.press indexes the source-backed facts above and links to the original. Something wrong? Corrections policy · Report an error