<- ALL CYBER NEWS

High

Apple, iOS, macOS, CVE-2026-43810, Patch, Kernel

iOS 26.6 Security Update: Apple Fixes 87 Flaws, macOS 155

Apple's iOS 26.6 security update fixes 87 flaws and macOS Tahoe 26.6 fixes 155, led by remote kernel bug CVE-2026-43810. Update urgency and affected versions.

Apple's iOS 26.6 security update patches 87 vulnerabilities, and macOS Tahoe 26.6 patches 155 — the standout is CVE-2026-43810, a remote kernel-memory-corruption flaw, and while Apple reports no active exploitation, you should update now. The July 28, 2026 release wave also covered macOS Sequoia 15.7.8 (138 fixes), macOS Sonoma 14.8.8 (127 fixes), Safari, and roughly 100 fixes each in watchOS, tvOS, and visionOS. None of the advisories mention in-the-wild exploitation — but the volume and the nature of the top bug are the story.

CVE-2026-43810 drew the most attention because it can be triggered remotely. Jamf's Adam Boynton put it plainly: a remote user "may be able to corrupt kernel memory, because remote changes the economics of an attack chain considerably." NVD rates the flaw CVSS 9.8 with a memory-corruption weakness class (CWE-119). Apple's advisory language — that a bug "may lead to unexpected system termination or kernel memory corruption" — is the company's standard, conservative phrasing for exactly the kind of defect researchers routinely develop into full remote code execution once the patch is available to study.

That last point is why "no exploitation reported" should not translate into "no rush." The moment Apple ships a fix, security researchers and threat actors alike begin patch-diffing — comparing the patched and unpatched binaries to reconstruct the vulnerability. For a remotely triggerable kernel bug, the window between a patch shipping and a working exploit existing is measured in days, and every unpatched device sits inside that window. The friction, as Mac admins noted, is real: a mid-cycle point release carrying 87 to 155 CVEs forces enterprise teams to validate compatibility before mass deployment, and MDM deferral windows quietly extend the exposure.

What is CVE-2026-43810 and why does it matter?

It is a memory-corruption vulnerability that a remote attacker may be able to use to corrupt kernel memory — the most privileged region of the operating system. Kernel-memory corruption is the classic foundation for privilege escalation and code execution, and the "remote" qualifier is what makes it notable: it removes the need for local access or a user to run something, shortening the attack chain considerably. Apple has not reported it being exploited, but its severity and remote reachability put it at the top of this update's priority list.

Which Apple devices need this update and how urgent is it?

Effectively all of them, and the urgency is high even without a confirmed exploit. iPhone and iPad users should install iOS/iPadOS 26.6; Mac users on the current release should install macOS Tahoe 26.6, with Sequoia and Sonoma users covered by 15.7.8 and 14.8.8 respectively. Internet-exposed Macs and mobile devices that leave the corporate network should be first in line, because they are the ones a remote kernel bug can actually reach.

Platform

Release

Vulnerabilities fixed

iOS / iPadOS

26.6

87

macOS Tahoe

26.6

155

macOS Sequoia

15.7.8

138

macOS Sonoma

14.8.8

127

watchOS / tvOS / visionOS

latest

~100 each

Notable CVE

CVE-2026-43810

Remote kernel memory corruption (CVSS 9.8, CWE-119)

Our read

A 242-CVE update across iOS and macOS is less a single emergency than a stark reminder that patch latency is the real exposure. Our 2025 analysis of CISA's KEV catalog found the median gap between a vulnerability's disclosure and its first observed exploitation was 26 days, and 20% were exploited on or before the day they were disclosed — which is to say the safe assumption is that the clock starts the instant Apple publishes, not the instant someone posts a working exploit. This is the compliance-as-evidence pillar in practice: "we're patched" is a claim, and the useful version of it is a timestamped, per-device record of which builds are actually deployed versus which are still sitting in a deferral window. On a bug like CVE-2026-43810, the difference between those two is the whole risk.

FAQ

Which iOS version has the fix? iOS and iPadOS 26.6, released July 28, 2026. It patches 87 vulnerabilities including the notable CVE-2026-43810.

Is CVE-2026-43810 being exploited? Apple reports no in-the-wild exploitation at release. It is still high priority because it is a remotely triggerable kernel-memory-corruption bug, and patch-diffing shortens the time to a working exploit.

Do older macOS versions get the fix? Yes — macOS Sequoia 15.7.8 and Sonoma 14.8.8 ship the security fixes for their branches alongside macOS Tahoe 26.6.

Should I update immediately or wait? Update within a standard emergency window (24–72 hours), prioritizing phones and internet-exposed Macs. Waiting mainly benefits attackers doing patch analysis.

Sources: SecurityWeek · NVD — CVE-2026-43810 · Apple security releases

Reporting by SecurityWeek, with commentary from Jamf; CVSS and CWE details per NVD; version and fix counts per Apple's security advisories.

Related: Ubuntu snap-confine local root (CVE-2026-8933) · What CVSS misses: EPSS, KEV and patch prioritization

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.