iOS 26.6.1: Apple’s 29 CVE Fixes, and the Telephony Entry That Stood Out

Apple iPhone 18 Pro Photos app Apple Reference Image
Image: Apple

iOS 26.6.1 and iPadOS 26.6.1, released August 17, 2026, carried 29 documented CVE entries, according to Apple’s own support article at support.apple.com/en-us/148282. The document states plainly that it lists no actively exploited issue: there is no “may have been exploited” language anywhere in it.

Apple iPhone 18 Pro 2up
Apple's iPhone lineup. The Telephony fix in this release concerns cellular network authentication. Image: Apple

The single Telephony entry in that list, credited to a group of academic researchers, describes a network-position attack against IPSec authentication. The other 28 entries span Kernel, ImageIO, Audio, IOGPUFamily and roughly twenty WebKit fixes.

Key facts on iOS 26.6.1

ItemWhat Apple’s document shows
ReleaseiOS 26.6.1 and iPadOS 26.6.1
DateAugust 17, 2026
Sourcehttps://support.apple.com/en-us/148282
CVE entries29
Actively exploited issue listedNone
Component with the most entriesWebKit, roughly 20 of the 29
Non-WebKit componentsTelephony, ImageIO, IOGPUFamily, Audio, Kernel
Apple iPhone Duo colors
iPhone Duo. It ships with iOS 27, a later release than the iOS 26.6.1 update covered here. Image: Apple

The Telephony fix, in Apple’s own words

CVE-2026-65329 is the release’s Telephony entry. Apple’s own impact line reads: an attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic. Apple credits four researchers by name: Bedran Karakoc, Tobias Funke, Jacopo Clark and Katharina Kohls.

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

Apple’s document describes the fix by component and outcome only. It does not publish the mechanism an attacker would need, and this article does not either.

Apple Watch Series 12 2up
Apple Watch, shown for illustration. watchOS is not among the platforms this release covers. Image: Apple

Notable fixes among the other 28

CVEComponentApple’s impact descriptionCredited by Apple
CVE-2026-65346ImageIOProcessing an image may lead to arbitrary code executionMeta Red Team X – Nik Tsytsarkin
CVE-2026-64788IOGPUFamilyProcessing maliciously crafted web content may lead to memory corruptionf00l, 3ndy1, Minghao Lin, Arjanit Isufi
CVE-2026-65339AudioAn app may be able to leak sensitive user informationMeta Red Team X
CVE-2026-65330KernelAn app may be able to cause unexpected system termination or corrupt kernel memoryBhaswanth Chigurupati, Billy Jheng Bing Jhong, Pan Zhenpeng
CVE-2026-65343KernelA remote attacker may be able to cause unexpected system terminationNot specified in Apple’s summary
CVE-2026-65349KernelAn app may be able to cause unexpected system termination or read kernel memoryNot specified in Apple’s summary
CVE-2026-65347ImageIOProcessing an image may lead to a denial-of-serviceNot specified in Apple’s summary
CVE-2026-64778WebKit HistoryVisiting a maliciously crafted website may leak sensitive dataNot specified in Apple’s summary

Nearly all of the remaining WebKit entries share one description: processing maliciously crafted web content may lead to an unexpected Safari crash. Apple lists each as a separate CVE number rather than grouping them.

What the document does not claim

  • It does not describe any of the 29 issues as actively exploited.
  • It does not rank the entries by severity; every one gets the same format, a component name and one impact sentence.
  • It does not name which iPhone or iPad models are affected beyond the device list Apple publishes for the release.
  • It does not connect any entry to the WebKit-only credits Apple published the same day for iOS 18.7.10, covered separately.

Where this sits against Apple’s other August releases

iOS 26.6.1 shares its August 17 date with iOS 18.7.10, macOS Tahoe 26.6.2 and visionOS 26.6.1 on Apple’s index, though each carries its own separate CVE list. watchOS is not among them; the last watchOS entry on Apple’s index before this date is watchOS 26.6, dated July 27. Apple’s current phones, iPhone 18 Pro and iPhone Duo, ship with iOS 27 rather than iOS 26.6.1.

What Apple has not said

Apple has not published exploitation details, proof-of-concept code or reproduction steps for any of the 29 entries, consistent with its usual practice on these documents. It has not stated whether any of the four Telephony researchers reported the issue through its bug bounty program, and its September 9 event press materials make no mention of this release at all.

As of Saturday, September 12, 2026, no update to the iOS 26.6.1 document has been posted, and the next entries on Apple’s index are iOS 26.6.2, dated September 8, followed by iOS 27 on September 14.