# Apple released patches for 90+ vulnerabilities across iOS, macOS, and other platforms…

Published: 2026-05-12 · Severity: high
Canonical: https://vorant.io/reports/ea322daf-58be-4d47-b919-4c76e9f9ad40/apple-released-patches-for-90-vulnerabilities-across-ios-macos-and-other

> Apple released patches for 90+ vulnerabilities across iOS, macOS, and other platforms, including critical flaws allowing arbitrary code execution and privilege escalation.

Apple has disclosed multiple vulnerabilities affecting iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. The most severe vulnerabilities permit arbitrary code execution with kernel privileges and root-level privilege escalation. Several flaws enable attackers to execute code through maliciously crafted images, media files, or web content. Kernel memory corruption and information disclosure vulnerabilities are also present. Additional issues include sandbox escapes, privacy bypass mechanisms, Gatekeeper bypasses, and various denial-of-service conditions. The vulnerabilities span core OS components, WebKit, image processing libraries, media frameworks, and system services. Exploitation could allow attackers to install programs, modify or delete data, create accounts with full privileges, access sensitive user information, or cause system instability. Users with administrative rights face higher risk than those with restricted privileges.

Apple has released updates across all affected product lines, with version numbers ranging from iOS/iPadOS 15.8.8 through 26.5 and macOS versions from Sonoma 14.8.7 through Tahoe 26.5. No active exploitation has been reported. The advisory recommends immediate patching after testing, implementing least-privilege access controls, enabling anti-exploitation features, restricting web content, deploying endpoint detection solutions, and conducting security awareness training. Organizations should prioritize updates for internet-facing systems and devices with administrative access.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1837, CVE-2026-28819, CVE-2026-28840, CVE-2026-28870, CVE-2026-28877, CVE-2026-28915, CVE-2026-28918, CVE-2026-28919, CVE-2026-28923, CVE-2026-28925, CVE-2026-28936, CVE-2026-28940, CVE-2026-28943, CVE-2026-28951, CVE-2026-28952, CVE-2026-28956, CVE-2026-28958, CVE-2026-28959, CVE-2026-28964, CVE-2026-28969, CVE-2026-28972, CVE-2026-28974, CVE-2026-28976, CVE-2026-28977, CVE-2026-28978, CVE-2026-28986, CVE-2026-28988, CVE-2026-28990, CVE-2026-28991, CVE-2026-28992, CVE-2026-28995, CVE-2026-28996, CVE-2026-39869, CVE-2026-39870, CVE-2026-43654, CVE-2026-43655, CVE-2026-43656, CVE-2026-43659, CVE-2026-43661, CVE-2026-43668

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-apple-products-could-allow-for-arbitrary-code-execution_2026-047

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ea322daf-58be-4d47-b919-4c76e9f9ad40/apple-released-patches-for-90-vulnerabilities-across-ios-macos-and-other.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
