Apple has released one of the most significant rounds of security updates in months, releasing patches for iPhone, iPad, and Mac devices running both modern and older versions of its operating system . The fixes address serious vulnerabilities in key components of the company’s ecosystem, including WebKit, the operating system kernel, Wi-Fi , and application sandboxing mechanisms. The new releases include iOS 26.5, iPadOS 26.5, and macOS Tahoe 26.5, which fix more than 50 vulnerabilities.

Also released were macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, iOS 18.7.9, iPadOS 18.7.9, iPadOS 17.7.11, as well as updates for older platforms such as iOS 16.7.16 and iOS 15.8.8. This strategy shows that Apple continues to invest in security even for devices released more than a decade ago.
See also: Google discovered zero-day attacks created with the help of AI
Focus on WebKit and the core of the system
Particular emphasis was placed on fixes related to WebKit, the rendering engine used not only by Safari but also by a large portion of web views in iOS and macOS apps. According to the company's technical reports, the vulnerabilities could allow user data to be leaked, memory corruption through malicious content, or even Safari processes to crash.
The updates also fix security vulnerabilities in the kernel , which are considered among the most dangerous, as they potentially allow arbitrary code execution with elevated privileges. In some cases, attacks could lead to complete control of the device by an attacker.
Apple has addressed issues related to integer overflows, out-of-bounds writes, race conditions, and Gatekeeper bypasses via malicious ZIP files or disk images. These are techniques often used in targeted cyberattacks and malware campaigns.
Concern about Wi-Fi and wireless networks
One of the most important elements of the new update cycle concerns Wi-Fi attack potential. Apple has patched a vulnerability that could allow code execution kernel-level.
At the same time, denial-of-service issues were fixed in mDNSResponder , a service critical for features like AirPlay and automatic device discovery on the network. Security experts point out that such vulnerabilities are particularly dangerous on public or unsecured Wi-Fi networks.
See also: cPanel – WHM: Fix 3 new vulnerabilities
Apple also issued patches that restrict apps' access to protected data, such as contact lists, system information , and camera metadata, and addressed issues that allowed apps to escape the sandbox isolation environment.

Support even for older iPhones and iPads
One of the most notable elements of the announcement is that Apple is continuing to support devices from 2014 and 2015. Security updates were extended to models like the iPhone 6s, iPhone 7, first-generation iPhone SE, iPad Air 2, and iPad mini 4.
For these devices, the fixes focus primarily on Notification Services, addressing a bug that could leave deleted notifications stored on the device. While this particular issue is not considered as critical as the kernel flaws, it demonstrates that Apple is seeking to maintain a basic level of protection even on hardware that has passed its end of life.
This policy differentiates Apple from much of the Android market, where many devices lose security support completely after a few years.
The contribution of the cybersecurity community
In its official security reports, Apple credited researchers from organizations like Google Project Zero, Google Threat Analysis Group, Palo Alto Networks, and Trend Micro Zero Day Initiative. The presence of so many different research groups underscores the importance of collaboration between tech giants and the international cybersecurity community.
Also of interest is the reference to researchers who worked in collaboration with artificial intelligence tools, showing that AI is starting to play an increasingly important role in identifying vulnerabilities.
See also: Cisco patches serious vulnerabilities in enterprise products

What users should do immediately
While Apple does not report that these vulnerabilities are already being actively exploited in attacks, experts recommend immediately installing the updates. Users should restart their devices after installation to fully apply the kernel and network fixes.
At the same time, it is recommended to avoid unknown applications, suspicious links and unsecured wireless networks. For those who have devices that are no longer supported, experts warn that they should not be used for sensitive tasks such as online banking, storing passwords or managing personal data.
This latest move by Apple confirms that cybersecurity remains a top priority for the company, at a time when attacks against mobile and desktop platforms are constantly increasing in complexity and frequency.
