iOS 18.7.10: About 120 Security Fixes for iPhone XS and Three Other Devices

Apple iPhone 18 Pro 2up
Image: Apple

iOS 18.7.10 and iPadOS 18.7.10, released August 17, 2026, list on the order of 120 CVE entries across more than 30 components, according to Apple’s own support article at support.apple.com/en-us/148287. The release is available for exactly four devices: iPhone XS, iPhone XS Max, iPhone XR and iPad 7th generation.

Apple iPhone 18 Pro Photos app Apple Reference Image
Apple's iOS interface. iOS 18.7.10 is a much older release than the current iOS 27. Image: Apple

Apple’s document contains no “may have been exploited” language anywhere in it. Two of those four devices, iPhone XS and iPhone XS Max, also appear on Apple’s separate vintage and obsolete list, which governs hardware service and parts, not software updates.

Key facts on iOS 18.7.10

ItemWhat Apple’s document shows
ReleaseiOS 18.7.10 and iPadOS 18.7.10
DateAugust 17, 2026
Sourcehttps://support.apple.com/en-us/148287
Available foriPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
CVE entriesOn the order of 120
Actively exploited issue listedNone
Component with the most entriesWebKit, 40 or more of the total
Apple iPhone Duo colors
iPhone Duo. It ships with iOS 27, not the iOS 18.7.10 update covered here. Image: Apple

Why two of these four devices are also on Apple’s vintage list

Apple’s vintage and obsolete page, last updated August 31, 2026, defines vintage as a product Apple stopped selling more than five and less than seven years ago. iPhone XS and iPhone XS Max both appear on that list. Vintage status affects hardware service and parts availability at Apple and its authorized providers; it does not affect whether a device keeps receiving software security updates, and iOS 18.7.10 is Apple’s own evidence of that distinction.

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

Apple’s current phones, iPhone 18 Pro and iPhone Duo, are nowhere near vintage status and ship with iOS 27 rather than iOS 18.7.10.

Apple Watch Series 12 2up
Apple Watch, shown for illustration. This update does not include watchOS. Image: Apple

What the roughly 120 entries cover

Apple’s document lists CVE entries across Accessibility, AirDrop, APFS, App Store, AppleDouble, Audio, AVEVideoEncoder, BackgroundAssets, Books, Contacts, CoreAudio, CoreMedia, CoreUI, CoreVideo, curl, Foundation, FrontBoard, Game Center, Heimdal, ImageIO, IOSkywalkFamily, IOSurfaceAccelerator, Kernel, libarchive, libc, Libnotify, Managed Configuration, Maps, mDNSResponder, MediaRemote, MobileAccessoryUpdater, Model I/O, Pro Res, SceneKit, Siri, Storage, WebKit, WebRTC, Wi-Fi and WorkoutKit. Kernel accounts for more than 20 of those entries and WebKit for more than 40.

Notable individual entries, in Apple’s own wording

CVEComponentApple’s impact descriptionCredited by Apple
CVE-2026-43723MediaRemoteAn app may be able to gain root privilegesNot specified in Apple’s summary
CVE-2026-64747AVEVideoEncoderAn app may be able to execute arbitrary code with kernel privilegesFranco Belman (Blackwing Intelligence)
CVE-2026-43818ImageIOProcessing a maliciously crafted image may lead to arbitrary code executionNot specified in Apple’s summary
CVE-2026-64740Game CenterA malicious app may be able to break out of its sandboxNot specified in Apple’s summary
CVE-2026-64726Wi-FiAn attacker in physical proximity may be able to corrupt process memoryNot specified in Apple’s summary
CVE-2026-64735KernelA remote attacker may be able to bypass network filtersNot specified in Apple’s summary

Apple’s document also lists CVE-2026-28973 in libc and CVE-2026-43776 in AppleDouble as sandbox and file-processing issues respectively, and separately patches two curl CVEs, 2026-3784 and 2026-3783, plus one in libarchive, 2026-4424, both third-party open-source components Apple ships and updates alongside its own code.

A cluster of credits in one place: Model I/O and SceneKit

Within the same document, a set of Model I/O and SceneKit entries, covering 3D model and file parsing, carries credit to a single researcher, stratan (@5tratan), on ten or more separate CVE numbers in this one release. Apple’s format for that credit is the same single-line style it uses throughout the document.

What Apple has not said

Apple has not published exploitation details, proof-of-concept code or reproduction steps for any of the roughly 120 entries. It has not stated why iPhone XS, iPhone XS Max, iPhone XR and iPad 7th generation receive a combined update rather than four separate ones, and it has not said whether these four devices will continue receiving security updates on the same schedule as its current lineup.

As of Saturday, September 12, 2026, no newer entry for these four devices has appeared on Apple’s security index, and the vintage and obsolete list they partly sit on was last updated August 31, 2026. Apple’s September 9 event press materials do not mention iOS 18.7.10, iPhone XS or the vintage list at all.