A few hours after the initial release, Apple provided the documentation. 29 vulnerabilities have been fixed, more than two-thirds of them in the browser engine. One vulnerability was identified by a research group from Bochum, while nine others were discovered by OpenAI.
The security update was released on the evening of August 17th, initially without any information about its contents. The security notes are now available – and they also explain why the update was only available through the developer channel for a week. For comparison: The major iOS 26.6 update in July closed 78 vulnerabilities.
Key Facts at a Glance
- Apple lists 29 vulnerabilities with their own CVE identifier in the security advisories for iOS 26.6.1.
- 21 of them concern WebKit and its sub-areas – that is, the engine behind Safari and every browser on the iPhone.
- Four researchers from Ruhr University Bochum reported a gap in mobile communications coverage.
- Nine entries are attributed to the OpenAI security team.
- Apple itself states that the fixes were first available in the betas of iOS 27.
WebKit dominates the list
The distribution is clear. Of 29 entries, 19 are for WebKit, with one each for WebKit History and WebKit Storage – a total of 21, or 72 percent of the entire list.
| Component | Number |
|---|---|
| WebKit | 19 |
| kernel | 3 |
| ImageIO | 2 |
| WebKit History | 1 |
| WebKit Storage | 1 |
| Audio | 1 |
| IOGPUFamily | 1 |
| Telephony | 1 |
Most WebKit entries describe the same process: malicious web content crashes Safari or corrupts memory. Three kernel vulnerabilities go further – in the worst case, a program can read or damage kernel memory; in one case, a remote attacker is sufficient.
In practical terms, this means that the most dangerous way into the system is via the browser, and because every browser on iPhone and iPad is based on WebKit, switching to Chrome or Firefox won't help. Only an update will help.
A gap from Bochum
One entry stands out because it doesn't concern the browser. Under "Telephony," Apple describes a vulnerability that allowed an attacker with a privileged network position to bypass IPSec authentication and intercept network traffic. It was fixed through improved state management.
The vulnerability was reported by Bedran Karakoc, Tobias Funke, Jacopo Clark, and Katharina Kohls from Ruhr University Bochum. It affects only iPhones from the iPhone 11 onward, not the iPad – iPads without a cellular module are not affected by the telephony component.
A privileged network position presupposes that someone already controls the data path, for example via a manipulated Wi-Fi network or a fake cell tower. For travelers and users of public networks, this is not a theoretical scenario.
Nine findings come from OpenAI
One name stands out as appearing repeatedly in the list: Apple attributes nine of the 29 entries to OpenAI's security division, specifically its in-house Codex tool and researcher Amy Burnett. All nine relate to WebKit.
This continues a trend that has been evident since spring. In May, an AI system already uncovered vulnerabilities in macOS, and at the end of June, it was revealed that Apple was prioritizing its security updates due to AI-driven attacks. Both sides are arming themselves with the same tools: whoever automatically finds vulnerabilities can report or exploit them.
For the evaluation of this update, this means one thing above all: Any vulnerabilities that a tool repeatedly uncovers can also be uncovered from the other side using the same tool. Therefore, the time between release and personal installation is considered shorter than it was two years ago.
Why the update comes from the iOS 27 betas
Apple prefaces the list with a sentence explaining the unusual path of this update: The fixes were first available in the betas of iOS 27 and iPadOS 27. They were therefore not developed for the 26-inch generation, but backported from the current development branch.
This fits with the events of the past week. A backport explains both the short-term deployment attempt on August 10th and the subsequent additional test round in the developer channel.
For users of the beta versions, this has a practical consequence: Those already running iOS 27 Beta have these fixes. Everyone else will receive them with iOS 26.6.1 – several weeks before the final version.
What needs to be done now
The list contains no indication that any of the vulnerabilities have already been actively exploited – Apple usually explicitly marks such cases. This alleviates some of the pressure, but doesn't change the order: From the moment of publication, the descriptions are publicly available, including the affected component and the type of vulnerability.
macOS Tahoe 26.6.2 and iOS 18.7.10 for older devices are documented in parallel. Apple had not yet provided the notes for visionOS 26.6.1 at the time of publication. We explain the structure of Apple's security updates separately.
For you, this means: If you skipped the update tonight, do it now. With 21 browser vulnerabilities, a single visit to a compromised website is enough to launch an attack – and that's the method you can least control.
When a security update is released, do you pay attention to which components are affected, or do you install everything as soon as it's available? Let us know in the comments if you'd be interested in such a list.
- iOS 26.6.1 is here: Apple makes the final release
- iOS 27 Beta 6: Apple is entering the home stretch
- App tracking: Apple needs to restructure its data collection process in Germany


