The updates include macOS Tahoe 26.6, iOS 26.6, iPadOS 26.6, watchOS 26.6, tvOS 26.6, and visionOS 26.6, as well as updates to older versions of macOS 15 Sequoia and macOS 14 Sonoma.
According to CVE.org, watchOS, tvOS, and visionOS 26.6 updates alone address at least 194 unique vulnerabilities.
In macOS Tahoe 26.6, Apple fixed about 155 vulnerabilities, including problems that could allow obtaining root privileges, exiting the sandbox, or bypassing the Gatekeeper system. The update also prevents unauthorized access to sensitive user data, and limits the ability of external applications to track the user’s fingerprint or raise their permissions within the system.
The update also included improvements in memory handling, to protect against malicious audio files, in addition to fixes related to kernel memory corruption, memory overflows, and remote denial-of-service attacks.
Apple also addressed issues that could allow malicious apps to delete files without permission, cause an unexpected system shutdown, read kernel memory, access contacts, or bypass code signing rules.
As for the macOS Sonoma 14.8.8 and macOS Sequoia 15.7.8 updates, they address critical vulnerabilities in several components, including the App Store, Apple Account, Neural Engine, Audio, Contacts, Crash Reporter, Control Center, Game Center, and the system kernel.
On iPhone and iPad, iOS 26.6 and iPadOS 26.6 address more than 75 vulnerabilities that affect the Neural Engine, App Store, kernel, WebKit, Wi-Fi, Siri, and other apps.
These updates are available for iPhone 11 and later, iPad Pro 12.9 3rd generation and later, iPad Pro 11 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Apple also released watchOS 26.6 updates for Apple Watch Series 6 and later, tvOS 26.6 for all Apple TV HD and Apple TV 4K devices, and visionOS 26.6 for all Apple Vision Pro devices.
The update also included the Safari 26.6 browser on the Sonoma and Sequoia systems, with fixes for approximately 12 vulnerabilities in WebKit and WebRTC, including problems with authorization, memory manipulation, data leakage, and crashes in the WebAssembly Micro Runtime, in addition to vulnerabilities that may allow interface deception, click fraud attacks, or denial of service.
Apple recommends that users install updates quickly due to the number and severity of the vulnerabilities.
iPhone and iPad users can install the update by going to Settings, then General, then Software Update. On Mac devices, the update is done through System Settings, then General, then Software Update.
Safari can also be updated to version 26.6 from the Software Updates panel on Sonoma and Sequoia, while Apple Watch, Apple TV, and Vision Pro updates are installed from each device’s system update settings.
The company recommends activating automatic updates where available, to ensure future security patches arrive in a timely manner.
Apple has not indicated in its current alerts that there is an active exploitation of these vulnerabilities. However, the size and breadth of the updates makes installing them a necessary step, especially for users of older supported macOS versions, as Sonoma 14.8.8 and Sequoia 15.7.8 updates include critical fixes that Tahoe 26.6 alone does not cover. (ghacks)