Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe
87 for iOS, 155 for macOS Tahoe — Apple's biggest patch drop of the quarter lands this week, with no in-the-wild exploitation reported.
Key Takeaways
|
A vendor patch-cycle disclosure, not an incident — the story is the sheer volume, the point releases to deploy, and the handful of kernel and remote flaws worth prioritizing.
CUPERTINO, CALIF. — Apple has shipped one of the largest patch cycles of 2026, fixing 87 vulnerabilities in iOS 26.6 and iPadOS 26.6 and 155 in macOS Tahoe 26.6 in a single coordinated release, alongside dozens more in its older macOS lines and roughly 100 in each of its other operating systems. The advisories are dated July 27, 2026, and Apple notes no in-the-wild exploitation of any of the flaws.
As reported by SecurityWeek, the update spans Apple's entire platform: iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro and Safari all received fixes on the same day. This is a routine vendor patch-cycle disclosure rather than a breach or an active-attack event — but the volume alone makes it a defender priority. This piece leads with the numbers, then the highest-severity items and the deployment guidance that matters this week.
| At a Glance | |
|---|---|
| Field | Details |
| What | A single-cycle Apple security release across all operating systems |
| iOS / iPadOS 26.6 | 87 vulnerabilities fixed |
| macOS Tahoe 26.6 | 155 vulnerabilities fixed |
| macOS Sequoia 15.7.8 | 138 vulnerabilities fixed |
| macOS Sonoma 14.8.8 | 127 vulnerabilities fixed |
| watchOS / tvOS / visionOS | Roughly 100 fixed in each |
| Safari | Nearly a dozen fixed |
| Active exploitation | None mentioned in Apple's advisories |
| Advisory date | July 27, 2026 (reported July 28) |
What Apple Shipped
The headline figures are 87 vulnerabilities patched in iOS 26.6 and iPadOS 26.6 and 155 in macOS Tahoe 26.6, but they are only the top of a much larger release. Apple also shipped macOS Sequoia 15.7.8, which resolves 138 security issues, and macOS Sonoma 14.8.8, which resolves 127. Many of the same flaws were patched across all three macOS lines, so the counts overlap rather than stack.
Beyond the Mac and mobile numbers, Apple patched roughly 100 vulnerabilities in each of watchOS, tvOS and visionOS, and the latest Safari update fixes close to a dozen browser flaws, including issues that could expose sensitive data or crash the browser. On iOS and iPadOS alone, the fixed flaws span the usual defender-relevant categories: access to sensitive user data, arbitrary code execution, denial-of-service conditions, file-system modification, security-feature bypasses, UI spoofing and privilege escalation. In short, this is a full-platform maintenance drop, not a targeted single-CVE fix.
The Highest-Severity Items
Apple does not publish CVSS scores in its advisories, so severity has to be read from the described impact. The item drawing the most outside attention is CVE-2026-43810, a kernel flaw where, in Apple's words, a remote user may be able to cause unexpected system termination or corrupt kernel memory. Jamf senior enterprise strategy manager Adam Boynton singled it out to SecurityWeek, noting that the remote vector "changes the economics of an attack chain considerably" — remote memory corruption is far more valuable to an adversary than a bug that first requires local code execution. The fix is credited to researchers at STAR Labs.
It is not the only kernel item worth attention. The iOS advisory lists a long run of kernel fixes for use-after-free, out-of-bounds and race-condition issues that could cause unexpected system termination or let an app write kernel memory, plus a buffer overflow reachable by connecting to a malicious NFS server. Elsewhere in the release, a CloudAttestation flaw could let a maliciously crafted app bypass code-signing enforcement, a MediaRemote path-handling issue could let an app gain root privileges, and several ImageIO and Model I/O bugs could lead to arbitrary code execution or memory disclosure from a crafted image or 3D-model file. One WebKit fix is notably credited to researchers working "with Claude, Anthropic," a small marker of how AI-assisted review is now surfacing memory-safety bugs in shipping software.
Actively Exploited CVEs and CISA KEV Status
The most important line for triage is what Apple did not say: the advisories make no mention of any of these vulnerabilities being exploited in the wild. That is a meaningful distinction from Apple's periodic emergency patches, which explicitly flag flaws that "may have been actively exploited" and often coincide with commercial-spyware activity. Nothing in this release carries that language, and none of the fixes were attributed in the reporting reviewed to any spyware vendor.
That does not make the flaws harmless. Apple's disclosure model means details become public the moment patches ship, giving researchers and adversaries alike a roadmap to unpatched devices. Whether any of these CVEs are later added to CISA's Known Exploited Vulnerabilities (KEV) catalog is not something the current advisories address; the prudent posture is to treat the release as pre-emptive hardening and to keep an eye on KEV over the coming weeks rather than to assume the absence of a KEV entry today is permanent.
What Defenders Should Push in MDM Environments
For fleets under management, the action is straightforward: get iOS 26.6, iPadOS 26.6 and the appropriate macOS release — Tahoe 26.6, Sequoia 15.7.8 or Sonoma 14.8.8 — approved and deployed. In an MDM environment such as Jamf, Intune or Kandji, that means staging the updates through a test ring first, confirming no line-of-business app breaks, then pushing to the broader estate with a short enforcement deadline. Managed software-update commands and declarative device management let administrators schedule installs and set a hard cutoff, which matters when a cycle this large means a long tail of stragglers. This is the same coordinated discipline The CyberSignal has flagged around large multi-vendor patch days.
Prioritization inside the rollout is worth a moment's thought. The remote kernel item and the code-signing-bypass and root-escalation flaws are the ones that most change an attacker's options, so devices that are internet-exposed, shared or high-value should lead the deployment wave. It is also a reminder that Apple's platform security is a moving target: recent CyberSignal coverage has tracked targeted Apple hardware fixes, boot-chain research affecting older iPhones and Apple's own move to open-source post-quantum cryptography — all of which underline that keeping the OS current is the single highest-leverage control most organizations have.
Open Questions
A few things remain unresolved at publication, and The CyberSignal is not filling them in. Apple does not itemize a full severity ranking, so the relative risk of the 155 macOS or 87 iOS flaws beyond the impact descriptions is a matter of interpretation rather than published fact. The precise per-OS breakdown across iPadOS, watchOS, tvOS and visionOS — which flaws are shared and which are platform-specific — is not fully enumerated in the material reviewed, and the exact counts for those OSes are described in reporting as approximate.
The other open question is what happens next. No active exploitation is reported today, but Apple's public advisories effectively start a clock, and history shows some post-disclosure flaws are weaponized within weeks. Defenders should treat the absence of exploitation as a window to patch, not as a reason to defer, and watch for any KEV additions, follow-up advisories or independent proof-of-concept work as the picture develops.
The CyberSignal Analysis
The figures and impact descriptions above come from Apple's advisories and the reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts.
Signal 01 — The Number Is the Story, and It Is a Deployment Story
Our reading is that 87 and 155 are less remarkable as security findings than as logistics. A cycle this size, landing across every Apple platform at once, is a test of an organization's update machinery more than its threat intelligence. The teams that will absorb this cleanly are the ones with MDM rings, deadlines and rollback plans already wired up; the ones that will struggle are those that still treat OS updates as an end-user choice.
The takeaway is to measure the response by time-to-full-coverage, not by whether any single CVE looks alarming. When the fix is "install the update," the only real variable is how fast and how completely you can make that happen across the fleet.
Signal 02 — "No Known Exploitation" Is a Window, Not an All-Clear
The absence of in-the-wild exploitation is the detail most likely to be misread. Our assessment is that it should accelerate patching, not excuse delay: Apple's model publishes the vulnerability details the instant the patch exists, which hands attackers a differential to work backward from. The quiet period between disclosure and first exploitation is precisely the window defenders are being handed.
We would treat this release as pre-emptive hardening with a shelf life. Organizations that patch inside the window convert a public disclosure into a non-event; those that wait for a KEV entry or a headline are choosing to find out whether they were on the wrong side of the clock.
Signal 03 — Watch the Remote Kernel Flaw, Not the Headline Count
The most durable detail, in our view, is buried in the impact text rather than the totals: a remote user reportedly able to corrupt kernel memory is a different class of problem from the many local-app bugs around it. Remote reach removes the hardest precondition an attacker usually faces, which is why the Jamf comment about attack economics is the sharpest observation in the coverage.
Our guidance is to let impact language, not raw counts, drive prioritization inside the rollout. Remote-corruption, code-signing-bypass and root-escalation items deserve to lead the deployment wave; the long tail of local denial-of-service fixes can follow. The headline number tells you how much work there is — the impact descriptions tell you what to do first.