in

Apple Patches 29 Flaws in iOS 26.6.1, Including an Image Bug That Can Run Code on Your iPhone

Apple shipped iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 on August 17, 2026, and the most serious fix in the batch sits in ImageIO, the framework every Apple device uses to open image files. Apple’s advisory says that processing a maliciously crafted image “may lead to arbitrary code execution”, which in plain terms means an attacker can run their own code on your phone through a picture. Apple’s security note for the iOS and iPadOS release lists 29 separate CVE entries.

How an image file turns into an attack

The ImageIO flaw is tracked as CVE-2026-65346. Apple describes it as an integer overflow addressed with improved input validation. An integer overflow happens when a program calculates a value larger than the memory it set aside for the result, and the spillover can be steered by whoever crafted the file. Because ImageIO sits underneath Messages, Mail, Safari and most third party apps, the vulnerable code runs wherever an image gets rendered rather than inside one app you could simply avoid.

Hosting 75% off

Apple credits the report to Nik Tsytsarkin of Meta Red Team X. The same researcher is credited with CVE-2026-65339, an Audio bug that Apple says could let an app leak sensitive user information. A second ImageIO entry, CVE-2026-65347, is a denial of service issue reported by Geonha Lee.

One other item deserves attention from anyone who works out of cafes and coworking spaces. CVE-2026-65329, filed under Telephony, describes an attacker in a privileged network position bypassing IPSec authentication and intercepting network traffic. It was reported by researchers at Ruhr University Bochum.

The bulk of the list is the browser engine

Of the 29 CVE entries in the iOS advisory, more than half sit in WebKit, WebKit History or WebKit Storage. That matters more on an iPhone than on a laptop, because every browser on iOS renders pages using WebKit, so a WebKit hole cannot be sidestepped by switching to Chrome or Firefox on your phone. Three further entries are kernel bugs, including a use after free that Apple says a remote attacker could exploit to cause unexpected system termination.

An AI bug hunter turns up in Apple’s credits

Read the acknowledgements closely and one name appears nine times: “OpenAI Codex Security – Amy Burnett”. Nine of the WebKit CVEs in this release carry that credit, either alone or shared with a human researcher. Apple does not explain the methodology behind any credit line, but the volume stands out in a list where almost every other researcher appears once.

For anyone who writes or reviews code for clients, that is the story inside the story. Automated review is moving past style and lint warnings into finding memory corruption bugs in one of the most heavily audited codebases in the world. Work of that kind used to be the preserve of specialist security teams, and it is now showing up in vendor credits at scale.

Which devices get the fix, and how to install it

Apple lists the affected products as iPhone 11 and later, iPad Pro 12.9 inch third generation and later, iPad Pro 11 inch first generation and later, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later. On the Mac side the fix ships in macOS Tahoe 26.6.2.

On iPhone and iPad, open Settings, then General, then Software Update. On a Mac, open System Settings, then General, then Software Update. If your device supports automatic updates, this is the type of release that argues for leaving them switched on. If you are not certain a past update actually installed, we walked through the checks in this guide to confirming an Apple security update landed.

The catch for anyone on an older iPhone

Anything older than an iPhone 11 does not appear on Apple’s affected list, which is a different thing from being safe. Devices that fall out of the support window stop receiving these advisories altogether, and image parsing bugs have historically drawn interest from commercial spyware vendors precisely because they demand so little from the target. Across Pakistan and the Gulf, a large share of working phones sit well past that line, often bought second hand and running whatever version they shipped with. For a freelancer whose phone holds client files, payment app access and two factor codes, the sharper question is not whether to install this patch but how many more patches that handset will ever be offered.

Sources: Apple, About the security content of iOS 26.6.1 and iPadOS 26.6.1; Apple security releases; The Register.

Hosting 75% off

Written by Ahmed Shaami

Modular tubular steel handrail and clamp fittings on a modern construction site

Why Adaptability Matters in Modern Construction Projects

Anthropic Passes OpenAI in Quarterly Revenue for the First Time