Description

On September 15, 2025, Apple rolled out a significant security update for iOS 26 and iPadOS 26, addressing 27 vulnerabilities across 23 critical system components. The update supports iPhone 11 and newer models, as well as various iPad devices starting from the iPad Pro 12.9-inch 3rd generation. Several core systems, including the Kernel, IOKit, and Sandbox, received patches. The Kernel fix addresses a logic flaw that could expose network communications, while Sandbox updates resolve permission issues allowing apps to bypass security restrictions. Fixes were also issued for the Apple Neural Engine to prevent out-of-bounds access that could cause system instability. Media components such as CoreAudio, CoreMedia, and Audio received updates to prevent app crashes and memory corruption from malicious files. Several privacy-related vulnerabilities were also addressed. AppleMobileFileIntegrity was patched to stop unauthorized access to user data, and the Bluetooth stack was enhanced to better redact sensitive data. Updates to the Text Input system prevent lock screen keyboards from displaying private suggestions, while Siri improvements ensure Private Browsing tabs are securely protected. Additionally, Call History now has stronger redaction features, and a fix in the Notes app prevents locked notes from being exposed through cache data. WebKit, the engine behind Safari, received extensive attention due to its central role in web-based attacks. Multiple patches were issued to stop crashes, prevent unauthorized access to sensors, and fix use-after-free vulnerabilities within the WebKit Process Model. These updates are essential given Safari’s wide usage across the Apple ecosystem. Apple credited security researchers from Trend Micro Zero Day Initiative, Kandji, and several independent professionals for responsibly disclosing the flaws. Users are urged to install this update immediately to protect against potential exploits and maintain device security.