Apple Closes Browser-to-Kernel Paths Across Its Fleet

Most of this release is browser-surface cleanup. The real risk sits in the small set of kernel memory bugs and sandbox escapes, because those are the cases where a malicious website can move from a browser crash to device-level compromise. Apple shipped 37 fixes across iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2. Most of the issues are in WebKit, but the high-value ones include CVE-2026-43724 and CVE-2026-39868 in the kernel, plus WebKit flaws that can push restricted web content outside the sandbox. Apple also said at least four defects were identified using AI, which points to a sourcing trend, not a new attacker capability.

Part of the PlainSec briefing for 2026-07-02

Sources