- Sources: Apple security release notes, HN discussion
- Summary: Apple released iOS 26.6.1 and iPadOS 26.6.1 on 2026-08-17 and states the update delivers fixes first made available in the iOS 27 and iPadOS 27 betas. The Telephony entry, CVE-2026-65329, lets an attacker in a privileged network position bypass IPSec authentication and intercept traffic. The ImageIO entry, CVE-2026-65346, reaches arbitrary code execution from a processed image. Three Kernel entries cover memory corruption and kernel memory disclosure. Nine of the WebKit CVEs are credited to OpenAI Codex Security. Apple marks no entry in this advisory as actively exploited.
- Why it matters: In Apple's own terms the ImageIO flaw reaches arbitrary code execution from processing an image and the Telephony flaw lets an attacker in a privileged network position intercept network traffic, and the advisory states nothing about whether either requires user interaction.
- Follow-up: Track whether Apple later marks any of these entries as exploited, and whether AI-attributed credit blocks of this size recur in Apple advisories.
send feedback on this story