Vulnerabilities & Exploits
Apple Closes Browser-to-Kernel Paths Across Its Fleet Most of this release is browser-surface cleanup. The real risk sits in the small set of kernel memory bugs and sandbox escapes, because those are the cases where a malicious website can move from a browser crash to device-level compromise.
Apple shipped 37 fixes across iOS 26.5.2 , iPadOS 26.5.2 , macOS Tahoe 26.5.2 , and Safari 26.5.2 . Most of the issues are in WebKit, but the high-value ones include CVE-2026-43724 and CVE-2026-39868 in the kernel, plus WebKit flaws that can push restricted web content outside the sandbox. Apple also said at least four defects were identified using AI, which points to a sourcing trend, not a new attacker capability.
5 sources · Jul 1
CVE-2026-39868 NVD KEV
CVSS 9.1 CRITICAL: this issue was addressed with improved input validation. EPSS 1% (66th percentile).
CVE-2026-43724 NVD KEV
CVSS 7.8 HIGH: the issue was addressed with improved input sanitization. EPSS 0.3% (25th percentile).
Timeline Sources Jul 1 Zero Day Initiative Blog
Zero Day Initiative — The June 2026 Apple Security Update Review
For June 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2.
original Jul 1 SecurityWeek
Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.
original Jun 30 NCSC-NL Advisories
Kwetsbaarheden verholpen in Apple iOS en iPadOS
Apple heeft meerdere kwetsbaarheden verholpen in iOS en iPadOS.
original Part of the PlainSec briefing for 2026-07-01
Every edition of this story: Apple Closes Browser-to-Kernel Paths Across Its Fleet
More from today
Vulnerabilities & Exploits
Apple Closes Browser-to-Kernel Paths Across Its Fleet Most of this release is browser-surface cleanup. The real risk sits in the small set of kernel memory bugs and sandbox escapes, because those are the cases where a malicious website can move from a browser crash to device-level compromise.
Apple shipped 37 fixes across iOS 26.5.2 , iPadOS 26.5.2 , macOS Tahoe 26.5.2 , and Safari 26.5.2 . Most of the issues are in WebKit, but the high-value ones include CVE-2026-43724 and CVE-2026-39868 in the kernel, plus WebKit flaws that can push restricted web content outside the sandbox. Apple also said at least four defects were identified using AI, which points to a sourcing trend, not a new attacker capability.
5 sources · Jul 1
CVE-2026-39868 NVD KEV
CVSS 9.1 CRITICAL: this issue was addressed with improved input validation. EPSS 1% (66th percentile).
CVE-2026-43724 NVD KEV
CVSS 7.8 HIGH: the issue was addressed with improved input sanitization. EPSS 0.3% (25th percentile).
Timeline Sources Jul 1 Zero Day Initiative Blog
Zero Day Initiative — The June 2026 Apple Security Update Review
For June 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2.
original Jul 1 SecurityWeek
Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.
original Jun 30 NCSC-NL Advisories
Kwetsbaarheden verholpen in Apple iOS en iPadOS
Apple heeft meerdere kwetsbaarheden verholpen in iOS en iPadOS.
original Part of the PlainSec briefing for 2026-07-01
Every edition of this story: Apple Closes Browser-to-Kernel Paths Across Its Fleet
More from today