Apple iOS 26.6.1 / macOS Tahoe 26.6.2 security content (17 Aug 2026)
Apple released iOS 26.6.1 and iPadOS 26.6.1 and macOS Tahoe 26.6.2 on 17 August 2026 (security-content pages published 20 August). The iOS advisory includes ImageIO integer overflow CVE-2026-65346, where processing an image may lead to arbitrary code execution; Telephony CVE-2026-65329, where an attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic (iPhone 11 and later); Kernel use-after-free CVE-2026-65343 (remote unexpected system termination); and multiple WebKit memory-safety issues. Apple does not publish CVSS scores on that page. Safari 26.6.1 followed on 18 August for macOS Sonoma and Sequoia. This is separate from CVE-2026-65400 (macOS Screen Sharing), which CISA added to KEV on 18 August.
- Product
- Apple iOS, iPadOS, macOS Tahoe, Safari
- Versions
- iPhone 11 and later; listed iPad models; macOS Tahoe; Safari on Sonoma/Sequoia
- Exploited in Australia?
- unknown
- Patch to
- iOS/iPadOS 26.6.1; macOS Tahoe 26.6.2; Safari 26.6.1
Primary: Apple: iOS 26.6.1 and iPadOS 26.6.1 security content · Vendor: Apple security releases · CVE: CVE-2026-65346, CVE-2026-65329, CVE-2026-65343, CVE-2026-65400 · Apple: macOS Tahoe 26.6.2 security content
