Apple Updates Everything - SANS Internet Storm Center
PatchiOSmacOSOur summary
Apple has rolled out a comprehensive suite of security updates for its entire ecosystem, including iOS, macOS, iPadOS, watchOS, visionOS, and tvOS. The release addresses a massive list of Common Vulnerabilities and Exposures (CVEs), ranging from kernel memory corruption and privilege escalation flaws to significant bugs in WebKit, ImageIO, and the Kernel.
Notable fixes include CVE-2026-43689 and CVE-2026-43786, which allow apps to gain root privileges, and multiple issues such as CVE-2026-43686 that enable kernel memory corruption via malicious NFS servers. Users are strongly advised to install these updates immediately to protect against potential exploits involving sensitive data leakage, remote code execution, and system instability.
Below is the opening; the full story is at SANS Internet Storm Center.
From SANS Internet Storm Center
CVE-2022-3437: A user in a privileged network position may be able to leak sensitive user information.
Affects Heimdal x x x CVE-2026-20683: An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.
Affects Apple Account x x x x…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.