Apple patches 168 vulnerabilities across iOS, macOS, Safari
Apple released security updates on 27 July 2026 addressing 168 CVEs across iOS, iPadOS, macOS, Safari, tvOS, visionOS, and watchOS, enabling arbitrary code execution, privilege escalation, and data disclosure.
CERT-FR advisory CERTFR-2026-AVI-0938 documents a large coordinated patch release by Apple addressing multiple critical vulnerabilities across its ecosystem. The affected products span iOS versions before 18.6, iPadOS before 18.6, macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, Safari before 18.6, tvOS before 18.6, visionOS before 3.6, and watchOS before 11.6. The advisory identifies risks including arbitrary code execution, privilege escalation, data confidentiality compromise, integrity violations, denial of service, and security policy bypass. Apple released eight security bulletins (128066–128073) on 27 July 2026 to address the issues. Defenders should prioritize patching all affected platforms immediately, as the scope and variety of impacts suggests potential for both targeted and opportunistic exploitation.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0938
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free