LIVE · cybersecurity feed
Live wire
vulnerability

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.

zeroday.news ·

Apple has released significant security updates for its iOS/iPadOS and macOS operating systems, addressing a substantial number of vulnerabilities. The updates, released on Monday, August 17th, include iOS/iPadOS versions 26 and 18, and macOS version 26. This release follows a smaller macOS-specific update approximately two weeks prior that targeted a single screen-sharing vulnerability.

The current comprehensive update is notable for patching a total of 108 vulnerabilities across the affected platforms. This volume suggests a broad range of security issues have been identified and remediated by Apple. The previous, more focused macOS update specifically addressed a screen-sharing flaw that was not reported to affect iOS or iPadOS devices.

Vulnerabilities patched in such large updates typically span various categories, including memory corruption issues, privilege escalation flaws, arbitrary code execution vulnerabilities, and information disclosure bugs. These types of flaws can arise in different components of an operating system, such as kernel drivers, system libraries, user-space applications, and network stacks. Exploitation of these vulnerabilities could potentially allow attackers to gain unauthorized access, execute malicious code, or compromise user data.

For users, the primary mitigation against these types of vulnerabilities is to apply the vendor-provided security updates as soon as they become available. Apple's update mechanism typically prompts users to install new versions, or users can manually check for updates through their device settings. Keeping operating systems and applications up to date is a fundamental security hygiene practice that helps protect against known exploits.

Given the breadth of vulnerabilities addressed, it is likely that the patched issues could have affected a wide range of devices running the prior versions of iOS/iPadOS and macOS. Products in this category commonly have a large global user base, making timely patching critical for maintaining the security posture of millions of devices. The specific technical details of each vulnerability are typically disclosed by Apple in accompanying security advisories, which provide insights into the nature of the flaws and their potential impact.

This substantial security release underscores the ongoing challenge of maintaining software security in complex operating systems. Vendors like Apple regularly release updates to address newly discovered vulnerabilities, often through a combination of internal security audits, external researcher reports, and bug bounty programs. The continuous cycle of vulnerability discovery and patching is a critical aspect of modern software development and cybersecurity defense, aiming to protect users from evolving threats.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

phishinghigh

CISA gives feds 3 days to fix actively exploited Ray RCE bug

Phishing, malvertising attacks could target devs to gain access to private corporate networks

vulnerabilitycritical

NASA Ground Control Software Flaw Enables Unauthenticated Commands

Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers

CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1

breach

BGP Role model: tracking the adoption of RFC 9234

RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.

security

Meta Ran Ads for an App That Promised to Nudify Female Politicians

One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.