iOS 18.7.10 and iPadOS 18.7.10, released August 17, 2026, list on the order of 120 CVE entries across more than 30 components, according to Apple’s own support article at support.apple.com/en-us/148287. The release is available for exactly four devices: iPhone XS, iPhone XS Max, iPhone XR and iPad 7th generation.
Apple’s document contains no “may have been exploited” language anywhere in it. Two of those four devices, iPhone XS and iPhone XS Max, also appear on Apple’s separate vintage and obsolete list, which governs hardware service and parts, not software updates.
Key facts on iOS 18.7.10
| Item | What Apple’s document shows |
|---|---|
| Release | iOS 18.7.10 and iPadOS 18.7.10 |
| Date | August 17, 2026 |
| Source | https://support.apple.com/en-us/148287 |
| Available for | iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation |
| CVE entries | On the order of 120 |
| Actively exploited issue listed | None |
| Component with the most entries | WebKit, 40 or more of the total |
Why two of these four devices are also on Apple’s vintage list
Apple’s vintage and obsolete page, last updated August 31, 2026, defines vintage as a product Apple stopped selling more than five and less than seven years ago. iPhone XS and iPhone XS Max both appear on that list. Vintage status affects hardware service and parts availability at Apple and its authorized providers; it does not affect whether a device keeps receiving software security updates, and iOS 18.7.10 is Apple’s own evidence of that distinction.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
Apple’s current phones, iPhone 18 Pro and iPhone Duo, are nowhere near vintage status and ship with iOS 27 rather than iOS 18.7.10.
What the roughly 120 entries cover
Apple’s document lists CVE entries across Accessibility, AirDrop, APFS, App Store, AppleDouble, Audio, AVEVideoEncoder, BackgroundAssets, Books, Contacts, CoreAudio, CoreMedia, CoreUI, CoreVideo, curl, Foundation, FrontBoard, Game Center, Heimdal, ImageIO, IOSkywalkFamily, IOSurfaceAccelerator, Kernel, libarchive, libc, Libnotify, Managed Configuration, Maps, mDNSResponder, MediaRemote, MobileAccessoryUpdater, Model I/O, Pro Res, SceneKit, Siri, Storage, WebKit, WebRTC, Wi-Fi and WorkoutKit. Kernel accounts for more than 20 of those entries and WebKit for more than 40.
Notable individual entries, in Apple’s own wording
| CVE | Component | Apple’s impact description | Credited by Apple |
|---|---|---|---|
| CVE-2026-43723 | MediaRemote | An app may be able to gain root privileges | Not specified in Apple’s summary |
| CVE-2026-64747 | AVEVideoEncoder | An app may be able to execute arbitrary code with kernel privileges | Franco Belman (Blackwing Intelligence) |
| CVE-2026-43818 | ImageIO | Processing a maliciously crafted image may lead to arbitrary code execution | Not specified in Apple’s summary |
| CVE-2026-64740 | Game Center | A malicious app may be able to break out of its sandbox | Not specified in Apple’s summary |
| CVE-2026-64726 | Wi-Fi | An attacker in physical proximity may be able to corrupt process memory | Not specified in Apple’s summary |
| CVE-2026-64735 | Kernel | A remote attacker may be able to bypass network filters | Not specified in Apple’s summary |
Apple’s document also lists CVE-2026-28973 in libc and CVE-2026-43776 in AppleDouble as sandbox and file-processing issues respectively, and separately patches two curl CVEs, 2026-3784 and 2026-3783, plus one in libarchive, 2026-4424, both third-party open-source components Apple ships and updates alongside its own code.
A cluster of credits in one place: Model I/O and SceneKit
Within the same document, a set of Model I/O and SceneKit entries, covering 3D model and file parsing, carries credit to a single researcher, stratan (@5tratan), on ten or more separate CVE numbers in this one release. Apple’s format for that credit is the same single-line style it uses throughout the document.
What Apple has not said
Apple has not published exploitation details, proof-of-concept code or reproduction steps for any of the roughly 120 entries. It has not stated why iPhone XS, iPhone XS Max, iPhone XR and iPad 7th generation receive a combined update rather than four separate ones, and it has not said whether these four devices will continue receiving security updates on the same schedule as its current lineup.
As of Saturday, September 12, 2026, no newer entry for these four devices has appeared on Apple’s security index, and the vintage and obsolete list they partly sit on was last updated August 31, 2026. Apple’s September 9 event press materials do not mention iOS 18.7.10, iPhone XS or the vintage list at all.