
Apple released iOS 26.6 on July 27 , 2026 , a critical update that fixes 87 security vulnerabilities across iOS and prepares iPhone for the arrival of iOS 27 in September. Among the findings are critical RCE vulnerabilities in ImageIO and WebKit , sandbox escapes in Game Center, as well as kernel flaws discovered with the help of Claude from Anthropic and Codex from OpenAI . We analyze what's new in iOS 26.6, what the most important security fixes are, and why every iPhone owner should upgrade immediately.
See also: iOS 27: 10 important new features and which iPhones will support them
iOS 26.6: The most critical vulnerabilities fixed
The most concerning fixes in iOS 26.6 concern zero-click and one-click vulnerabilities — that is, flaws that are exploited without any action from the user. The most important ones:
- CVE-2026-43818 (ImageIO): Processing a malicious image may lead to arbitrary code execution. ImageIO is a classic zero-click attack target, as images are automatically parsed in Messages, previews, and notifications.
- CVE-2026-64747 (AVEVideoEncoder): Buffer overflow that could allow code execution with kernel privileges — one of the most severe classes of vulnerabilities
- CVE-2026-43723 (MediaRemote): Path management flaw that could allow an application to gain root privileges, completely bypassing the iOS privilege separation model
- CVE-2026-43813 (CloudAttestation): Code signing enforcement bypass that undermines Apple's anti-malware protection
- CVE-2026-64767 (afpfs): Remote attacker can corrupt kernel memory via Apple Filing Protocol without authentication
Sandbox escapes: Violation of basic iOS protection
Two vulnerabilities directly fix iOS sandbox containment — the basic protection that keeps apps isolated from each other:
- CVE-2026-64740 (Game Center): Path verification flaw allows malicious applications to escape their sandbox
- CVE-2026-28973 (libc): Integer overflow with same result — application sandbox escape
Sandbox escape attacks are the "holy grail" for attackers, as they allow a seemingly harmless application to gain access to data from other applications or the system itself.
WebKit: 20+ vulnerabilities in Safari and embedded browsers
The WebKit engine that powers Safari and all browsers on iOS received the largest patch package. The main vulnerabilities:
- CVE-2026-64757: Memory management vulnerability discovered by Anthropic's Claude AI in collaboration with researchers — a revelation of AI-driven security gaining traction
- CVE-2026-64783: Second WebKit vulnerability discovered with the help of Z.ai's GLM
- CVE-2026-64728: iframe sandboxing policy violation
- CVE-2026-43821: Access control flaw that allows an application to read files outside its sandbox
- CVE-2026-64713: Privacy breach — history sniffing from websites

How AI helped uncover vulnerabilities
A particularly important element of iOS 26.6 is the ever-increasing role of artificial intelligence models in uncovering security vulnerabilities. In this update:
- Anthropic's Claude helped researchers identify WebKit memory issues
- OpenAI's Codex discovered multiple vulnerabilities in watchOS 26.6
- Z.ai's GLM found vulnerabilities in WebKit
- NVIDIA AI Red Team Discovers Sandboxing Bypasses in WebKit
This is a milestone: for the first time, Apple officially recognizes the role of AI models as security research tools on its platform. The rate of vulnerability discovery is skyrocketing — 210 CVEs in July 2026 compared to 37 in June.
New features beyond security fixes
Although iOS 26.6 is primarily a security update, it also brings a few minor changes:
- New notification "Blocked Contacts Limit Reached": Notifies the user when the maximum number of blocked contacts is reached
- Spotlight index optimization: Preparing for the new iOS 27 Search, reducing re-indexing time from weeks to hours
- Anti-snatching code: Found in beta code for automatic iPhone locking when grabbed from hands, but not yet enabled
- Enhanced contact protection: Two critical fixes for malicious contact cards that could leak sensitive information
Which iPhones support iOS 26.6
iOS 26.6 is available for all iPhones starting with iPhone 11 and later. iPadOS 26.6 is available for iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
How to install iOS 26.6 directly
The upgrade is free and can be completed in less than 10 minutes:
- Connect your iPhone to Wi-Fi and make sure it has at least 50% battery or charging
- Go to Settings → General → Software Update
- Click Download and Install
- The iPhone will download the update, ask for your passcode, and restart
- After rebooting, the entire process is completed in 5-8 minutes
Recommendation: As Apple begins to release details of patched vulnerabilities after the update, detailed exploits may appear in the coming days. Delaying installation increases the risk.
Frequently Asked Questions for iOS 26.6
How big is iOS 26.6 to download?
The update is between 1.2 and 2.4 GB depending on the iPhone model. Newer devices (iPhone 15 and later) are receiving a smaller package due to delta updates.
Will I lose data when upgrading?
No. iOS updates preserve all data, settings, apps, and photos. However, a precautionary backup via iCloud or Mac/PC is always recommended.
Will battery life be affected?
Point releases typically improve battery life through optimizations. If you notice reduced battery life, it is recommended to wait 48 hours for iOS to complete indexing and background processes.
Do I need to update my Apple Watch/Mac too?
Yes. Apple has released watchOS 26.6, macOS Tahoe 26.6, macOS Sequoia 15.7.8, tvOS 26.6, and visionOS 26.6 at the same time, all with important security fixes. Update all devices in your ecosystem.
Is iOS 26.6 the last update before iOS 27?
Probably not. Apple may release another iOS 26.7 update in late August with any emergency fixes, before iOS 27 in September.
Have any of these vulnerabilities been exploited yet?
Apple has not confirmed any active exploits at the time of release. However, ImageIO vulnerabilities are a classic target for commercial spyware like Pegasus, so immediate patching remains imperative.
See also: iPhone 18 Pro: 10 important features that change your iPhone
iOS 26.6 is one of Apple's most important security updates for 2026, both due to the huge number of fixes and the unprecedented use of artificial intelligence models in vulnerability discovery. The SecNews technical team recommends immediate installation on all compatible devices. Sources: Apple Security Advisory 128066, Zero Day Initiative, MacRumors, Forbes.
