CVE Tools

Apple Patches iOS and macOS - SANS Internet Storm Center

SANS Internet Storm CenterBy SANS Internet Storm Center9 min read

PatchiOSmacOS

Our summary

Apple has issued security updates for iOS and macOS to remediate a broad set of vulnerabilities affecting multiple system components. The release addresses numerous flaws, including kernel memory corruption that could allow privilege escalation, WebKit bugs enabling data exfiltration or crashes, and ImageIO defects leading to arbitrary code execution.

Key risks include potential remote exploitation through crafted web content or media files, as well as local sandbox escape vectors in frameworks like libc and MediaRemote. Users are advised to install the latest operating system updates to mitigate these threats.

Read at SANS Internet Storm Center

Below is the opening; the full story is at SANS Internet Storm Center.

From SANS Internet Storm Center

CVE-2026-28958: An app may be able to access sensitive user data.
Affects WebKit   x   CVE-2026-28973: A malicious app may be able to break out of its sandbox.
Affects libc   x   CVE-2026-28984: Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affe…

Continue at SANS Internet Storm Center

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store