Apple patches 140+ flaws in iOS macOS
Apple issued a large security update fixing over 140 vulnerabilities in iOS, iPadOS, and macOS Tahoe that can lead to code execution, privilege escalation, or denial of service.
ANSSI (CERT-FR) published an advisory summarizing three Apple security bulletins (148281, 148282, 148287) released on 17 August 2026, covering iOS versions prior to 18.7.10 and 26.6.1, iPadOS versions prior to 18.7.10 and 26.6.1, and macOS Tahoe versions prior to 26.6.2. The advisory lists an extensive set of CVEs—well over one hundred—affecting these platforms, with impacts ranging from arbitrary code execution and privilege escalation to remote denial of service, data integrity and confidentiality breaches, and security policy bypass.
No evidence of active exploitation, proof-of-concept code, or attacker attribution is included in the bulletin; it is a routine vendor patch advisory relayed by the French national CERT. Organizations running affected Apple products are advised to apply the vendor-supplied updates referenced in the official Apple security bulletins as soon as operationally feasible, given the breadth and severity range of the underlying flaws, several of which permit arbitrary code execution.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1038
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free