iOS 26.6 fixes 78 security holes
It is not the same to receive an update with new features that one can try on the phone than another one where the changes go internally. The latter are the boring ones, those that you leave until the end and that you only install when you get tired of seeing the notification. Paradoxically, the important ones tend to be the latter, because They are the ones that fix phone problems. This is the case of the recent update released by Apple. A patch to fix serious threats. The recent iOS 26.6 (and versions of other devices) is already in full distribution for compatible iPhones. In the update notice, Apple emphasizes that the software prepares the system for iOS 27although what is important are the problems it corrects. Among them, 14 entries aimed at one of the most critical areas of the system: the kernel. As stated in the changelog released by Applethe latest security update fixes serious windows to malicious code execution on devices. In total, there are 78 individual vulnerability entries linked to 87 CVE logs unique. There are more CVE records than entries because some of them group together several vulnerabilities. iPhone 17 pro Max One of the most important updates. It might seem that 26.6, released for all families of Apple devices, is a minor update, but the opposite is true: not installing it puts the use of our device at risk. Even though Apple is not aware that any of the vulnerabilities have been usedif exploited these would allow: An image that executes code alone. The devices allowed the processing of manipulated images to execute arbitrary code, without the user touching anything. Something similar to what NSO exploded in 2023 with BLASTPASS. CVE-2026-43818 From ordinary application to total control. One bug gave root privileges to an app, another, code execution with kernel privileges. A malicious application could take control of the device. CVE-2026-43723, CVE-2026-64747 Skip isolation between apps. Game Center and libc They allowed an application to escape its isolated execution environment. Another bug circumvented code signature checking, the mechanism that prevents unauthorized binaries from running on iOS. CVE-2026-64740, CVE-2026-28973, CVE-2026-43813 Fake contacts for telephone scams. An app could add contacts without authorization. For example, it would make it possible to add a fake bank number to the phonebook so that the user could trust when receiving the call. CVE-2026-64746, CVE-2026-64734 Bypass firewalls, VPN and parental controls. A remote attacker could bypass the system’s network filters. CVE-2026-64735 Access to a locked iPhone. The vulnerabilities would allow access to sensitive user information, even close to them: memory could be corrupted via WiFi. CVE-2026-43753, CVE-2026-64726 Advertising tracking without user knowledge. Several components made it possible to persistently identify the owner of the device in order to track him without his knowledge. CVE-2026-64741, CVE-2026-64733, CVE-2026-64713 Phishing with spoofed browser interface. Attackers could exploit vulnerabilities discovered in WebKit to spoof the Safari interface. This would allow the bank’s website to be imitated to trick the user into leaving their passwords on a false form. CVE-2026-64730 Despite the serious risks of all the vulnerabilities discovered, and patched in the recent update, we must emphasize that Apple found no evidence that they have been exploited to access the devices. Despite this, the advice is clear: updating costs nothing and can prevent a lot. Boring, but essential. Comes without the new Siriwithout changes to the interface and, as an improvement beyond the security fixes, iOS 26.6 and company prepare Spotlight indexing for iOS 27. Even so, this “boring” update is the only one that ensures the proper functioning of the devices. Which is exactly the main value to protect. Cover image | Montage with photo of Alejandro Alcolea and capture of Álvaro García In Xataka | The new Siri AI is here: two years later and with the help of Google, this is what Apple’s AI assistant does