27 July 2026 · 1 views

Don't wait to update: iOS 26.6 includes more than 75 security fixes

Don't wait to update: iOS 26.6 includes more than 75 security fixes

Apple's iOS 26.6 update stops attackers from using iPhone Mirroring, Siri, and more to gain user data. Here's what you need to know.

On Monday, just under a month following the arrival of the security-focused iOS 26.5.2, Apple made iOS 26.6 available to the general public. The latter includes over 75 security enhancements, 14 of which address kernel-related vulnerabilities.

10 of the now-patched kernel issues allowed apps to trigger unexpected system terminations, while others let apps access sensitive user data and write kernel memory. Apple resolved these issues through improved memory handling, memory management, state management, bounds checks, and more.

Subscribe to AppleInsider on YouTube

The iOS 26.6 fixes that keep your data safe

Additionally, iOS 26.6 prevents attackers from using iPhone Mirroring to access sensitive user data, as an Accessibility issue was resolved through state management improvements. Similar App Store and FrontBoard issues were resolved through improved checks and the use of HTTPS, respectively.

Smartphone lying on a wooden table with its colorful screen blurred and a large black Apple logo overlay; autumn leaves and a wooden box are in the background

iOS 26.6 contains multiple fixes that protect user data.

Apple also stopped apps from accessing user information through Game Center by improving data protection. Enhanced state management was used to fix similar Managed Configuration and WorkoutKit vulnerabilities.

iOS 26.6 also removed vulnerable Siri code, resolving an information disclosure issue that gave apps access to sensitive information about the user. Entitlement checks were employed to fix an NSColorPanel issue, once again preventing apps from leaking user data.

The Contacts app received three security enhancements as well, as processing a maliciously crafted contact will no longer leak sensitive user data, thanks to the iOS 26.6 update. Additionally, apps can no longer add contacts without user authorization, thanks to validation improvements.

How iOS 26.6 stops apps from gaining root access

Apple also took security measures to ensure that attackers with physical access to locked devices can't gain user data, as the company fixed a DriverKit and Wi-Fi issue.

Blue digital skull silhouette formed by dense white computer code on a dark background, symbolizing hacking, malware, or cybersecurity threats in a stylized, abstract way

iOS 26.6 prevents DOS attacks and stops apps from gaining root privileges.

iOS 26.6 also addresses a significant MediaRemote issue. The now-patched path handling vulnerability gave apps root privileges. Similarly. the iOS 26.6 update contains an Apple Books fix that prevents apps from accessing protected parts of the filesystem.

Multiple Model I/O issues were resolved as well, meaning that remote attackers can no longer cause unexpected app crashes on iOS 26.6. Three now-patched Scene I/O exploits enabled arbitrary code execution.

Apple also took measures to prevent apps from escaping their sandbox. The company did so by resolving Game Center and libc vulnerabilities with improved path validation and input validation, respectively.

Safari and WebKit fixes in iOS 26.6

Monday's iOS update also stops apps from using a WebKit issue to escape their sandbox. In total, iOS 26.6 contains eight WebKit fixes, meant to keep your data safe while browsing the web.

Two smartphones displaying Safari webpages on dark mode, demonstrating article summaries, relevant data cards, and highlights, with labels Safari, Article Summaries, Get Relevant Data, and Highlights on a dark background

iOS 26.6 contains multiple WebKit fixes.

Notably, iOS 26.6 includes a fix that stops websites from knowing the user visited a specific link. Apple also made UI improvements, as maliciously framed websites were found to spoof select UI elements.

As for the other WebKit patches, one of them prevents denial-of-service attacks, while two prevent Safari crashes on iOS 26.6. Apple similarly included fixes for mDNSResponder and Heimdal to prevent denial-of-service attacks.

Monday's software update contains a multitude of security enhancements. As Apple's website notes, fixes for Pro Res, WebRTC, AuthKit, the Apple Neural Engine, and more are present in iOS 26.6.Unlike other iOS releases, however, iOS 26.6 doesn't include fixes for vulnerabilities that were used in targeted attacks.

Even so, AppleInsider recommends installing it to ensure your devices have the latest security enhancements. Unlike the iOS 27 developer betas, which may contain bugs, glitches, and performance issues, the iOS 26.6 update should be installed by all users.

You May Also Like