On-screen text
Software Update
Automatic Updates
On
Beta Updates
iOS 26 Developer Beta
iOS 26.6
8.59 GB
This update includes bug fixes, security updates and optimizes the Spotlight index to prepare for iOS 27.
For information on the security content of Apple software updates, please visit this website:
https://support.apple.com/100100
Software updates, like this one, add new
Update Now
Update Tonight
If you select Update Tonight, iPhone will try to update when the device is locked and the battery has enough charge.
3:07 PM
iOS Version
About the security content of iOS 26.6 and iPadOS 26.6
About Apple security updates
For our customers' protection, Apple doesn't discuss, disclose, or confirm security issues until an investigation has occurred and patches or fixes are available. Recent releases are listed on the Apple Security Releases page.
Apple security documents reference vulnerabilities by CVE-ID when possible.
For more information about security, see the Apple Product Security page.
iOS 26.6 and iPadOS 26.6
Released July 27, 2023
Accessibility
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, and iPad mini 5th generation and later.
Impact: An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.
Description: This issue was addressed through improved state management.
CVE-2026-64732: Jorge Welch (@jorgewlch)
Accounts Framework
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An app may be able to fingerprint the user.
Description: This issue was addressed with improved data protection.
CVE-2026-64733: Rotyna Keller of Totally Not Malicious Software (paradisefacade.com)
App Store
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An app may be able to access sensitive user data.
Description: This issue was addressed with improved checks.
CVE-2026-43801: Rahul Raj
Apple Neural Engine
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: Processing a maliciously crafted image may lead to unexpected app termination or arbitrary code execution.
Description: An integer overflow was addressed with improved input sanitization.
CVE-2026-28924: Dun
AppleDouble
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: Processing a maliciously crafted image may lead to unexpected app termination or arbitrary code execution.
Description: A buffer overflow was addressed with improved bounds checking.
CVE-2026-43776: Irvin Wang, Peter Malone, Nicolas Rabinovich
Audio
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An app may be able to cause a denial-of-service.
Description: An out-of-bounds write issue was addressed with improved memory handling.
CVE-2026-64725: James Duffy
curl
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: Authentication credentials may be sent to a server on another origin.
Description: This is a vulnerability in open source code and Apple's software is among the affected products. The CVE-ID was assigned by the third party. Learn more about the issue and CVE-ID at GSBTO.
CVE-2026-3784: N/A
DriverKit
Foundation
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: A malicious app may be able to access sensitive user data.
Description: This issue was addressed with improved input sanitization.
CVE-2026-43714: an anonymous researcher
FontBoard
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An app may be able to access sensitive user data.
Description: This issue was addressed by using HTTPS when sending information over the network.
CVE-2026-64782: Huỳnh Tấn Nguyên
Home Center
CloudAttestation
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: A maliciously crafted app may be able to cause unexpected system termination or heap corruption.
Description: A validation issue was addressed with improved input validation.
CVE-2026-42813: Anton Pakhomov
Contacts
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An app may be able to add contacts without user authorization.
Description: An authorization issue was addressed with improved validation.
CVE-2026-64703: Rodolphe BRUNETTI (@brodolph) & Daniel Febrero
CoreAudio
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: Processing a maliciously crafted audio file may corrupt process memory.
Description: The issue was addressed with improved memory handling.
CVE-2026-43673: N.M.Praveen Nawaratne (@blockrat)
CoreAudio
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An app may be able to cause a denial-of-service.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2026-64744: Matthieu Mensire
CoreMedia
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: Processing a maliciously crafted video file may lead to unexpected process termination.
Description: A memory corruption issue was addressed with improved memory handling.
CVE-2026-43755: Nels Hellman
ImageIO
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An integer overflow was addressed with improved input sanitization.
Description: An integer overflow was addressed with improved input sanitization.
CVE-2026-43799: Billy Jheng Bing Jheng and Pan Zhengpeng (@peterpan0927) of STAR Labs SG Pte. Ltd.
Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An app may be able to cause unexpected system termination.
Description: This issue was addressed with improved memory handling.
CVE-2026-28931: Redon Gazik, Abhijeet Singh (linkedin.com/in/abhijeetg), Peter Malone, Omar Carrizo
Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: A remote process may be able to cause unexpected system termination or corrupt kernel memory.
Description: This issue was addressed with improved memory handling.
CVE-2026-43769: Billy Jheng Bing Jheng and Pan Zhengpeng (@peterpan0927) of STAR Labs SG Pte. Ltd.
Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An app may be able to cause unexpected system termination.
Description: An integer overflow was addressed with improved input validation.
CVE-2026-43766: N.M.Praveen Nawaratne (@blockrat)
Libnotify
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An attacker may be able to cause unexpected app termination.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2026-64729: Feng Xue and XGPT of Tlsat.com, Dun
Managed Configuration
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: An app may be able to access sensitive user data.
Description: An authorization issue was addressed with improved input validation.
CVE-2026-64743: Daniel Febrero
mDNSResponder
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: Processing a maliciously crafted image may lead to unexpected app termination or heap corruption.
Description: A buffer overflow was addressed with improved bounds checking.
CVE-2026-64775: stratan (@stratan), whdgovti
Model I/O
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Impact: A remote attacker may be able to cause unexpected application termination or heap corruption.
Description: An integer overflow was addressed with improved input validation.
CVE-2026-64772: whdsvdi