Old iPhones just got 122 security fixes in one update

Apple released security updates for iPhone, iPad and Mac on 17 August 2026, and the largest of them by a wide margin went to its oldest supported hardware. iOS 18.7.10 and iPadOS 18.7.10, which cover the iPhone XS, iPhone XS Max, iPhone XR and the 7th generation iPad, fix 122 separate vulnerabilities. iOS 26.6.1 and iPadOS 26.6.1, for everything newer, fix 29. macOS Tahoe 26.6.2 fixes 28.

None of them is flagged as being used in attacks. When Apple knows a flaw is under exploitation it says so in the advisory, in a standard sentence about being aware of a report that an issue may have been actively exploited. That sentence appears nowhere in this release. It is a maintenance round, not the kind of emergency patch that follows a spyware campaign.

The legacy branch touches 43 components

Across Apple's three advisories the updates name 132 distinct CVE identifiers between them, and the split is lopsided. The iOS 26.6.1 advisory lists 29 issues across eight components: WebKit and its history and storage layers, ImageIO, Audio, Kernel, Telephony and the graphics stack. The iOS 18.7.10 advisory lists 122 issues across 43 components, reaching into APFS, AirDrop, Contacts, Game Center, Maps, Siri, Wi-Fi, mDNSResponder and bundled open source code including curl and libarchive. Nineteen fixes appear on both branches, so the update for the older phones carries 103 that the current one does not. Apple does not explain the gap, and its advisories offer no detail beyond the impact lines.

An image, a phone call, a web page

Apple describes each fix with a single impact sentence and nothing further, so what follows is its wording rather than an analysis of the underlying bugs. On the current branch, a Telephony issue (CVE-2026-65329) meant an attacker in a privileged network position could bypass IPSec authentication and intercept network traffic, which in plain terms is somebody already sitting on the network path reading data that was meant to be protected. An ImageIO issue (CVE-2026-65346) meant processing an image could lead to arbitrary code execution, so the hostile content is an ordinary looking file rather than software a user has to install. Several WebKit issues, among them CVE-2026-65341 and CVE-2026-43794, meant maliciously crafted web content could corrupt memory, which is to say a booby trapped page can scramble the browser's internal state. On the legacy branch, an AVEVideoEncoder issue (CVE-2026-64747) meant an app could run code with kernel privileges, and an Accessibility issue (CVE-2026-64732) meant an attacker with physical access could reach sensitive data during iPhone Mirroring.

Apple publishes no severity scores

There are no CVSS ratings anywhere in the three advisories, and no affected version detail beyond the device lists, so anybody trying to rank these fixes has only Apple's impact wording to work from. HKCERT, which restated the release for Hong Kong readers a day later, rated the set as medium risk. The same limitation shaped our coverage of Apple's June WebKit round, and it is a standing feature of Apple advisories: the fix is public, the seriousness is not.

Update to 18.7.10, 26.6.1 or Tahoe 26.6.2

The fix is the update itself, and which one you need depends on the device. iPhone XS, XS Max, XR and 7th generation iPad owners take iOS 18.7.10 or iPadOS 18.7.10. iPhone 11 and later, along with iPad Air 3rd generation, iPad 8th generation, iPad mini 5th generation and the recent iPad Pro models, take iOS 26.6.1 or iPadOS 26.6.1. Macs running Tahoe take 26.6.2. Apple's own advisories for iOS 18.7.10, iOS 26.6.1 and macOS Tahoe 26.6.2 list every fix, and HKCERT's security bulletin gathers the identifiers in one place. Anyone with reason to think they are a target of commercial spyware should also check for an Apple threat notification, which the company now surfaces on the Lock Screen.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions