# Apple patches 168 vulnerabilities across iOS, macOS, Safari

Published: 2026-07-28 · Severity: elevated · Sectors: technology
Canonical: https://vorant.io/reports/4a6e47e8-5a9d-5bc7-bc6e-ba5eea4c61f5/apple-patches-168-vulnerabilities-across-ios-macos-safari

> Apple released security updates on 27 July 2026 addressing 168 CVEs across iOS, iPadOS, macOS, Safari, tvOS, visionOS, and watchOS, enabling arbitrary code execution, privilege escalation, and data disclosure.

CERT-FR advisory CERTFR-2026-AVI-0938 documents a large coordinated patch release by Apple addressing multiple critical vulnerabilities across its ecosystem. The affected products span iOS versions before 18.6, iPadOS before 18.6, macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, Safari before 18.6, tvOS before 18.6, visionOS before 3.6, and watchOS before 11.6. The advisory identifies risks including arbitrary code execution, privilege escalation, data confidentiality compromise, integrity violations, denial of service, and security policy bypass. Apple released eight security bulletins (128066–128073) on 27 July 2026 to address the issues. Defenders should prioritize patching all affected platforms immediately, as the scope and variety of impacts suggests potential for both targeted and opportunistic exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2025-43325, CVE-2026-20672, CVE-2026-23918 (poc), CVE-2026-28849, CVE-2026-28896, CVE-2026-28900, CVE-2026-28911, CVE-2026-28912, CVE-2026-28914, CVE-2026-28926, CVE-2026-28928, CVE-2026-28931, CVE-2026-28932, CVE-2026-28936, CVE-2026-28945, CVE-2026-28961, CVE-2026-28973, CVE-2026-28979, CVE-2026-28981, CVE-2026-28982, CVE-2026-28983, CVE-2026-3783, CVE-2026-3784, CVE-2026-39868, CVE-2026-39872, CVE-2026-39873, CVE-2026-39874, CVE-2026-39875, CVE-2026-39877, CVE-2026-43653, CVE-2026-43661, CVE-2026-43663, CVE-2026-43665, CVE-2026-43672, CVE-2026-43673, CVE-2026-43676, CVE-2026-43681, CVE-2026-43682, CVE-2026-43693, CVE-2026-43694

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0938

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4a6e47e8-5a9d-5bc7-bc6e-ba5eea4c61f5/apple-patches-168-vulnerabilities-across-ios-macos-safari.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
