iOS 26.6.1 and iPadOS 26.6.1, released August 17, 2026, carried 29 documented CVE entries, according to Apple’s own support article at support.apple.com/en-us/148282. The document states plainly that it lists no actively exploited issue: there is no “may have been exploited” language anywhere in it.
The single Telephony entry in that list, credited to a group of academic researchers, describes a network-position attack against IPSec authentication. The other 28 entries span Kernel, ImageIO, Audio, IOGPUFamily and roughly twenty WebKit fixes.
Key facts on iOS 26.6.1
| Item | What Apple’s document shows |
|---|---|
| Release | iOS 26.6.1 and iPadOS 26.6.1 |
| Date | August 17, 2026 |
| Source | https://support.apple.com/en-us/148282 |
| CVE entries | 29 |
| Actively exploited issue listed | None |
| Component with the most entries | WebKit, roughly 20 of the 29 |
| Non-WebKit components | Telephony, ImageIO, IOGPUFamily, Audio, Kernel |
The Telephony fix, in Apple’s own words
CVE-2026-65329 is the release’s Telephony entry. Apple’s own impact line reads: an attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic. Apple credits four researchers by name: Bedran Karakoc, Tobias Funke, Jacopo Clark and Katharina Kohls.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
Apple’s document describes the fix by component and outcome only. It does not publish the mechanism an attacker would need, and this article does not either.
Notable fixes among the other 28
| CVE | Component | Apple’s impact description | Credited by Apple |
|---|---|---|---|
| CVE-2026-65346 | ImageIO | Processing an image may lead to arbitrary code execution | Meta Red Team X – Nik Tsytsarkin |
| CVE-2026-64788 | IOGPUFamily | Processing maliciously crafted web content may lead to memory corruption | f00l, 3ndy1, Minghao Lin, Arjanit Isufi |
| CVE-2026-65339 | Audio | An app may be able to leak sensitive user information | Meta Red Team X |
| CVE-2026-65330 | Kernel | An app may be able to cause unexpected system termination or corrupt kernel memory | Bhaswanth Chigurupati, Billy Jheng Bing Jhong, Pan Zhenpeng |
| CVE-2026-65343 | Kernel | A remote attacker may be able to cause unexpected system termination | Not specified in Apple’s summary |
| CVE-2026-65349 | Kernel | An app may be able to cause unexpected system termination or read kernel memory | Not specified in Apple’s summary |
| CVE-2026-65347 | ImageIO | Processing an image may lead to a denial-of-service | Not specified in Apple’s summary |
| CVE-2026-64778 | WebKit History | Visiting a maliciously crafted website may leak sensitive data | Not specified in Apple’s summary |
Nearly all of the remaining WebKit entries share one description: processing maliciously crafted web content may lead to an unexpected Safari crash. Apple lists each as a separate CVE number rather than grouping them.
What the document does not claim
- It does not describe any of the 29 issues as actively exploited.
- It does not rank the entries by severity; every one gets the same format, a component name and one impact sentence.
- It does not name which iPhone or iPad models are affected beyond the device list Apple publishes for the release.
- It does not connect any entry to the WebKit-only credits Apple published the same day for iOS 18.7.10, covered separately.
Where this sits against Apple’s other August releases
iOS 26.6.1 shares its August 17 date with iOS 18.7.10, macOS Tahoe 26.6.2 and visionOS 26.6.1 on Apple’s index, though each carries its own separate CVE list. watchOS is not among them; the last watchOS entry on Apple’s index before this date is watchOS 26.6, dated July 27. Apple’s current phones, iPhone 18 Pro and iPhone Duo, ship with iOS 27 rather than iOS 26.6.1.
What Apple has not said
Apple has not published exploitation details, proof-of-concept code or reproduction steps for any of the 29 entries, consistent with its usual practice on these documents. It has not stated whether any of the four Telephony researchers reported the issue through its bug bounty program, and its September 9 event press materials make no mention of this release at all.
As of Saturday, September 12, 2026, no update to the iOS 26.6.1 document has been posted, and the next entries on Apple’s index are iOS 26.6.2, dated September 8, followed by iOS 27 on September 14.