Skip to content
Beveiligingsnieuws

WebKit Security Updates: macOS and iOS Patches

WebKit kwetsbaarheden

Apple has released a new set of WebKit security updates for macOS, iOS, and iPadOS. The latest releases focus heavily on WebKit—the web browser engine behind Safari—but they also include fixes for other system components. If you use Safari or any app that relies on WebKit, applying the update soon is a smart move.

According to Apple’s announcements, the patches address a large number of security defects, including vulnerabilities that may cause browser or process crashes, memory-related corruption, and disclosure of sensitive information.

What Apple fixed in the latest macOS update

The current macOS release rolling out now—macOS Tahoe 26.6.2—includes fixes for 28 security vulnerabilities. Of those, 21 are in WebKit. Apple notes that these WebKit issues could result in outcomes such as Safari or process crashes, memory corruption, and the exposure of sensitive data.

Beyond WebKit, the update also addresses seven additional issues affecting components including Audio, ImageIO, IOGPUFamily, and Kernel. Depending on the vulnerability, these fixes target risks like sensitive information disclosure, denial-of-service (DoS), arbitrary code execution, and memory corruption. Apple also mentions possibilities such as system termination and kernel memory disclosure or corruption.

iOS and iPadOS patches include WebKit and more

Alongside the macOS release, Apple has published iOS 26.6.1 and iPadOS 26.6.1 updates. These versions patch the same 28 vulnerabilities covered in the macOS update, with the majority again tied to WebKit.

Apple also included an extra security fix in the mobile updates: an authentication issue in Telephony. The company says attackers could potentially bypass IPSec authentication and intercept network traffic if the problem were left unpatched.

More security updates on the way

Apple’s timing suggests preparation for upcoming platform releases. The newly released iOS 26.6.1 and iPadOS 26.6.1 updates are described as likely setting the stage for iOS 27 and iPadOS 27, which are expected to arrive next month.

In addition to the “26.x” patches, Apple also announced updates for iOS 18.7.10 and iPadOS 18.7.10. These updates address more than 120 bugs, including over 40 WebKit-related issues.

Why WebKit vulnerabilities matter for everyday users

WebKit sits at the center of how many apps handle web content. When security flaws affect the browser engine, the impact can range from instability to more serious risk. Apple specifically mentions that the patched vulnerabilities could lead to crashes and memory corruption, along with disclosure of sensitive data.

In some cases, the flaws could potentially enable more severe outcomes such as sandbox escape and cross-origin data exfiltration. While exploitation details are not described in the announcement, the range of possible effects is a clear reminder that browser-engine security is critical for both privacy and system stability.

Kernel fixes expand the protection beyond the browser

It’s not only WebKit being updated. Apple also included fixes for vulnerabilities in the Kernel. In the mobile updates, the announcement highlights 18 kernel-related issues that could be exploited to corrupt kernel memory, crash the system, disclose kernel memory, bypass network filters, or write kernel memory.

Other outcomes Apple lists include leaking sensitive kernel state and gaining access to sensitive user data. These kernel vulnerabilities—because they target core system functionality—are often treated with high urgency in security advisories.

Security defects across many apps and frameworks

Beyond WebKit and the kernel, the new security updates also address defects across a broad set of components. Apple’s announcement references fixes in multiple areas, including:

  • Accessibility
  • AirDrop
  • App Store
  • AVEVideoEncoder
  • Contacts
  • CoreAudio and CoreMedia
  • Foundation
  • ImageIO
  • IOSkywalkFamily
  • Maps
  • MediaRemote
  • Model I/O
  • SceneKit
  • Siri
  • WebRTC

By covering so many frameworks, Apple’s update suggests a wide sweep of bug fixes intended to reduce both security risk and stability problems across the platform.

No public signs of in-the-wild exploitation

Apple’s announcement does not indicate that these specific vulnerabilities are actively exploited in the wild at this time. Even so, the fact that dozens of defects were patched—especially those affecting WebKit and the kernel—means the risk of exposure still exists for unpatched devices.

For many users, the practical takeaway is straightforward: keep your Apple devices updated, particularly when the update notes mention the browser engine and memory corruption risks.

What you should do next

If you rely on Safari or frequently open web content on your devices, applying the update promptly can help close known security gaps. Check your device’s update screen and install the relevant macOS, iOS, or iPadOS version mentioned in Apple’s security bulletin.

If you manage devices for an organization, make sure your patch process accounts for both mobile and desktop updates. Since the vulnerabilities span WebKit and deeper system components, delaying updates can extend the time during which devices remain exposed.

Conclusion

Apple’s latest WebKit security updates tackle dozens of vulnerabilities across macOS, iOS, and iPadOS, with the majority impacting WebKit. Along with browser-engine fixes that can lead to crashes, memory corruption, and data disclosure, Apple also patched additional risks in areas like the kernel and several media, accessibility, and networking-related frameworks.

Even without reports of widespread exploitation, the safest approach is to install the updates as soon as possible.

Source: https://www.securityweek.com/dozens-of-webkit-vulnerabilities-patched-with-fresh-macos-ios-security-updates/