The new iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 fix nearly 30 security vulnerabilities, according to support document . This is Apple’s third security release in three weeks. The continued development of artificial intelligence and its integration into code analysis processes have enabled faster vulnerability detection, leading to more frequent security updates.

Apple says the software includes security fixes that were previously added to the beta versions of iOS 27, iPadOS 27, and macOS Golden Gate. These fixes are critical to ensuring the integrity and security of devices, as security vulnerabilities can expose users to risks such as data loss and unauthorized access.
iOS 26.6.1 and macOS Tahoe 26.6.2: The vulnerabilities that are fixed
Specifically, the updates include fixes for an audio vulnerability that could allow an application to leak sensitive user information. This type of vulnerability is particularly dangerous as it can expose personal data without the user's knowledge. In addition, an image vulnerability could allow malicious users to execute commands on the system without permission.
See also: iOS 26.6, iPadOS 26.6 & macOS Tahoe 26.6: Dozens of security fixes
Additionally, three vulnerabilities in the kernel, the central part of the operating system that manages the basic functions of the device, were fixed. Vulnerabilities in the kernel are particularly concerning as they can allow access to system functions, potentially allowing malicious users to take over the device.

Also notable are fixes for several bugs in WebKit, the rendering engine used by Safari and other apps on iOS and macOS. Of the 29 CVEs (Common Vulnerabilities and Exposures) listed in the document, 21 are related to WebKit. These bugs could cause memory corruption or crashes in Safari, affecting the user experience and security when browsing the web.
Additionally, nine of the vulnerabilities are attributed to OpenAI Codex Security, highlighting the importance of collaborating with external security researchers to identify and fix bugs. This collaboration is critical to quickly addressing security vulnerabilities and protecting users.
See also: macOS Tahoe 26.5.2 and iOS 26.5.2: Updates coming soon
In iOS, Apple also fixed a telephony bug that could allow an attacker with a privileged network position to bypass IPSec authentication and intercept network traffic. IPSec authentication is an important technology for protecting data transmitted over networks, and bypassing it could allow sensitive information to be intercepted.

There is currently no evidence of active exploitation of these vulnerabilities, but Apple always recommends updating to new versions of iOS, iPadOS, and macOS as soon as possible. Now that the vulnerabilities have been made public, attackers could target devices that are still running older versions of the software. Updating devices quickly is critical to protecting against potential attacks.
See also: Apple releases second public betas of iOS 26.6 and macOS Tahoe 26.6
Apple also released iOS 18.7.10 and iPadOS 18.7.10 for devices that can't run iOS 26 and iPadOS 26.These updates ensure that even older devices receive critical security fixes, thus maintaining a basic level of protection for all users.
Updates can be installed by opening the Settings, selecting the General , and selecting Software Update. This process is simple and accessible to all users, ensuring that their devices remain secure and up-to-date.
