Description:
Apple has released iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, Safari 26.6, tvOS 26.6, watchOS 26.6 and visionOS 26.6 to fix the vulnerabilities in various Apple devices. The list of vulnerabilities information can be found at:
https://support.apple.com/en-gb/128066
https://support.apple.com/en-gb/128067
https://support.apple.com/en-gb/128068
https://support.apple.com/en-gb/128069
https://support.apple.com/en-gb/128070
https://support.apple.com/en-gb/128071
https://support.apple.com/en-gb/128072
https://support.apple.com/en-gb/128073
Reports indicated that proof-of-concept (PoC) exploit code is available for an information disclosure vulnerability (CVE-2026-3783). System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
Affected Systems:
- iPhone 11 and later
- iPad 8th generation and later, Air 3rd generation and later, mini 5th generation and later, Pro 11-inch 1st generation and later, Pro 12.9-inch 3rd generation and later
- macOS Sequoia prior to version 15.7.8
- macOS Sonoma prior to version 14.8.8
- macOS Tahoe prior to version 26.6
- Safari prior to version 26.6
- tvOS prior to version 26.6
- watchOS prior to version 26.6
- visionOS prior to version 26.6
Impact:
Depending on the vulnerabilities exploited, a successful attack could lead to remote code execution, denial of service, elevation of privilege, information disclosure, security restriction bypass, spoofing or tampering on an affected system.
Recommendation:
Patches for affected products are available. Users of affected systems should follow the recommendations provided by the vendor and take immediate actions to mitigate the risk.
The updates can be obtained through the auto-update mechanism. Users of affected systems should follow the recommendations provided by the vendor and take immediate actions to mitigate the risk.
More Information:
- https://support.apple.com/en-gb/128066
- https://support.apple.com/en-gb/128067
- https://support.apple.com/en-gb/128068
- https://support.apple.com/en-gb/128069
- https://support.apple.com/en-gb/128070
- https://support.apple.com/en-gb/128071
- https://support.apple.com/en-gb/128072
- https://support.apple.com/en-gb/128073
- https://www.hkcert.org/security-bulletin/apple-products-multiple-vulnerabilities_20260728
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-43325
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783 (to CVE-2026-3784)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4424
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20672
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23918
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28849
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28896
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28900
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28911 (to CVE-2026-28912)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28914
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28926
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28928
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28931 (to CVE-2026-28932)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28936
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28945
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28961
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28973
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28979
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28981 (to CVE-2026-28983)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39868
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39872 (to CVE-2026-39875)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39877
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43653
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43661
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43663
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43665
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43672 (to CVE-2026-43673)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43676
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43681 (to CVE-2026-43682)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43693 (to CVE-2026-43694)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43698 (to CVE-2026-43701)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43703 (to CVE-2026-43715)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43717 (to CVE-2026-43718)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43720 (to CVE-2026-43735)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43738 (to CVE-2026-43740)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43742 (to CVE-2026-43745)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43747 (to CVE-2026-43750)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43753 (to CVE-2026-43760)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43763 (to CVE-2026-43782)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43792 (to CVE-2026-43793)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43796 (to CVE-2026-43797)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43799 (to CVE-2026-43807)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43809 (to CVE-2026-43814)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43816 (to CVE-2026-43819)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43821 (to CVE-2026-43822)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64691 (to CVE-2026-64700)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64702 (to CVE-2026-64704)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64707 (to CVE-2026-64711)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64713
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64716
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64718 (to CVE-2026-64735)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64737 (to CVE-2026-64747)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64749
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64751
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64754 (to CVE-2026-64755)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64757 (to CVE-2026-64758)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64762 (to CVE-2026-64772)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64774 (to CVE-2026-64776)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64783