Vulnerabilities · 75 days ago
Apple Closes Browser-to-Kernel Paths Across Its Fleet Most of this release is browser-surface cleanup. The real risk sits in the small set of kernel memory bugs and sandbox escapes, because those are the cases where a malicious website can move from a browser crash to device-level compromise.
Apple shipped 37 fixes across iOS 26.5.2 , iPadOS 26.5.2 , macOS Tahoe 26.5.2 , and Safari 26.5.2 . Most of the issues are in WebKit, but the high-value ones include CVE-2026-43724 and CVE-2026-39868 in the kernel, plus WebKit flaws that can push restricted web content outside the sandbox. Apple also said at least four defects were identified using AI, which points to a sourcing trend, not a new attacker capability.
CVE-2026-39868 NVD KEV
CVSS 9.1 CRITICAL: this issue was addressed with improved input validation. EPSS 1% (66th percentile).
CVE-2026-43724 NVD KEV
CVSS 7.8 HIGH: the issue was addressed with improved input sanitization. EPSS 0.3% (25th percentile).
Timeline Sources 5 sources covering this story
Zero Day Initiative Blog Jul 1
Zero Day Initiative — The June 2026 Apple Security Update Review
For June 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2.
SecurityWeek Jul 1
Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.
NCSC-NL Advisories Jun 30
Kwetsbaarheden verholpen in Apple iOS en iPadOS
Apple heeft meerdere kwetsbaarheden verholpen in iOS en iPadOS.
NCSC-NL Advisories Jun 30
Kwetsbaarheden verholpen in Apple MacOS
Apple heeft meerdere kwetsbaarheden verholpen in macOS Tahoe.
CSIRT Italia / ACN Jun 30
Aggiornamenti di sicurezza Apple
Apple ha rilasciato aggiornamenti di sicurezza per risolvere diverse vulnerabilità presenti nei propri prodotti.
The Hacker News Jun 29
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
Apple ships iOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2 patching 30+ flaws, including AI-discovered WebKit CVEs and kernel bugs; no active exploitat
Entities CVE-2026-43724 CVE-2026-39868 Part of the PlainSec briefing for 2026-07-02
Editions Related stories
Vulnerabilities · 75 days ago
Apple Closes Browser-to-Kernel Paths Across Its Fleet Most of this release is browser-surface cleanup. The real risk sits in the small set of kernel memory bugs and sandbox escapes, because those are the cases where a malicious website can move from a browser crash to device-level compromise.
Apple shipped 37 fixes across iOS 26.5.2 , iPadOS 26.5.2 , macOS Tahoe 26.5.2 , and Safari 26.5.2 . Most of the issues are in WebKit, but the high-value ones include CVE-2026-43724 and CVE-2026-39868 in the kernel, plus WebKit flaws that can push restricted web content outside the sandbox. Apple also said at least four defects were identified using AI, which points to a sourcing trend, not a new attacker capability.
CVE-2026-39868 NVD KEV
CVSS 9.1 CRITICAL: this issue was addressed with improved input validation. EPSS 1% (66th percentile).
CVE-2026-43724 NVD KEV
CVSS 7.8 HIGH: the issue was addressed with improved input sanitization. EPSS 0.3% (25th percentile).
Timeline Sources 5 sources covering this story
Zero Day Initiative Blog Jul 1
Zero Day Initiative — The June 2026 Apple Security Update Review
For June 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2.
SecurityWeek Jul 1
Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.
NCSC-NL Advisories Jun 30
Kwetsbaarheden verholpen in Apple iOS en iPadOS
Apple heeft meerdere kwetsbaarheden verholpen in iOS en iPadOS.
NCSC-NL Advisories Jun 30
Kwetsbaarheden verholpen in Apple MacOS
Apple heeft meerdere kwetsbaarheden verholpen in macOS Tahoe.
CSIRT Italia / ACN Jun 30
Aggiornamenti di sicurezza Apple
Apple ha rilasciato aggiornamenti di sicurezza per risolvere diverse vulnerabilità presenti nei propri prodotti.
The Hacker News Jun 29
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
Apple ships iOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2 patching 30+ flaws, including AI-discovered WebKit CVEs and kernel bugs; no active exploitat
Entities CVE-2026-43724 CVE-2026-39868 Part of the PlainSec briefing for 2026-07-02
Editions Related stories