NEWS
Apple Pulled 38 iOS 26.6 Fixes Into 26.5.2
iOS 26.5.2 pulled 38 beta security fixes into public builds, then iOS 26.6.1 did the same with iOS 27, shrinking the window attackers get from Apple’s own notes.
Apple shipped iOS 26.5.2 on June 29, 2026, moving 38 listed security fixes out of the 26.6 betas and onto every supported iPhone. iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 landed the same day, each with the same one-line customer note: security fixes, no features.
Cupertino said it was cutting the wait because AI tools now shrink the time between a public fix and a working attack. There was no sign those bugs had already been used. The quieter change sat in the security notes themselves, which now treat the next beta as a live patch channel for the OS people already run.
What iOS 26.5.2 Patched on iPhone
iOS 26.5.2 is build 23F84. It is sold as a security-only drop for iPhone 11 and later, and Apple’s notes open with a sentence the company had not been putting on public point releases: the update delivers fixes that were first made available in the iOS 26.6 and iPadOS 26.6 betas. macOS Tahoe 26.5.2 is build 25F84, with the same line pointed at the Tahoe 26.6 beta.
THE JUNE 29 SECURITY DROP
| Product | Build | Apple’s opening note |
|---|---|---|
| iOS 26.5.2 | 23F84 | Fixes first in the iOS 26.6 betas |
| iPadOS 26.5.2 | 23F84 | Fixes first in the iPadOS 26.6 betas |
| macOS Tahoe 26.5.2 | 25F84 | Fixes first in the Tahoe 26.6 beta |
| Safari 26.5.2 | Not listed | Fixes first in the Tahoe 26.6 beta, for macOS Sonoma and Sequoia |
The security content of iOS 26.5.2 lists 38 CVE identifiers, most of them in WebKit, WebRTC, Web Extensions, and related web code that Safari and in-app browsers share. Three kernel bugs sit beside them, plus IOGPUFamily, two libxslt crashes, and a MobileAccessoryUpdater overflow that Apple added to the notes on July 27, 2026.
WebKit is the engine every iPhone browser has to use in most markets, so a malicious page can reach those bugs without a separate app install. One listed issue let a site pull data across origins. Another let a visit leak sensitive data through a permissions hole. WebKit Storage could let a site take clipboard data without a prompt. A separate WebKit bug let a malicious site process restricted web content outside the sandbox.
Kernel entries are narrower (they need an app on the device) and uglier if chained: unexpected shutdown, kernel memory writes, and leaks of kernel state. Apple did not tag any of the 38 as already exploited.
Apple Stopped Waiting for the Next Point Release
Until this drop, Apple’s default was to hold ordinary security work for the next numbered iOS, unless researchers found an active campaign against a hole nobody had seen. Developers still poke the next build in beta. That beta is public enough that a fix sitting there, while production phones stay on 26.5.1, is a map.
Apple said it was adapting to AI speeding up malicious hacking tools, and that it had to cut the time between a fix first going public and that fix reaching customers. The 26.6 betas had already published the work. 26.5.2 put the same work on phones that were never going to join a beta.
With recent AI advances, we are seeing vulnerability finding times dramatically reduce, which makes patching that much more difficult. Waiting for large updates to cover smaller known vulnerabilities over a long period of time might be a thing of the past now with such tools that even more rapidly search for any possible exploits.
Jake Moore, global cybersecurity advisor, ESET
26.5.1, shipped June 1, 2026, had no published CVE entries. It was a maintenance build for a charging issue on iPhone 17 and a shutdown bug on M5 Macs using certain enterprise network filters. 26.5.2 is the first 26.5 point release that reads as a full security bulletin, and it arrived 28 days after 26.5.1.
The Credit Lines Name Claude, Codex, and GLM
The same notes that justify the rush also show who is finding the holes. Apple still credits people. It now credits models next to them.
THE AI NAMES IN APPLE’S CVE CREDITS
- CVE-2026-43715: Milad Nasr and Nicholas Carlini with Claude, Anthropic, on a WebKit use-after-free that can corrupt memory.
- CVE-2026-43716: OpenAI Codex Security researchers Amy Burnett and Evan Lambert, with Tuan and Duc from Calif.io, on a WebKit bug that can crash Safari.
- CVE-2026-43707: OpenAI Codex Security’s Amy Burnett, with stratan of Almamater Technologies, on WebKit memory corruption that can crash a process.
- CVE-2026-43745: OpenAI Codex Security’s Amy Burnett and Khai Tran, on a WebKit out-of-bounds write that can crash Safari.
- CVE-2026-43663: A long WebKit crash list that includes “Using GLM From Z.AI” among human researchers.
- CVE-2026-43701: Aaron Grattafiori of the NVIDIA AI Red Team, on a WebKit sandbox issue.
That is the bind inside Apple’s own PDF. The company pulled 26.6 beta fixes onto 26.5.2 because models can turn a known bug into an exploit faster, and the credit block on those fixes already names Claude, Codex, and Z.AI’s GLM as finders. Calif.io, which shows up on more than one WebKit line, had also described a Mythos-aided memory-corruption path against Apple M5 silicon in May.
Labs outside that US circle have been advertising similar scanners. Tokyo-based Sakana AI has described Fugu as competitive on several of the same tests, and 360 Security Technology has pitched Tulongfeng against Mythos-class work. Apple does not say any of those tools drove the June 29 calendar. It did not have to. The credit file already proves models are in the bug pipeline.
iOS 26.6.1 Repeated the Backport for 27 Betas
If 26.5.2 had been a one-off, the 26.6 notes would have gone back to the old script. They did not.
THE PATCH CLOCK AFTER JUNE
- June 12, 2026: The US Commerce Department orders Anthropic to suspend foreign-national access to Claude Fable 5 and Mythos 5, and Anthropic takes both models down worldwide.
- June 29, 2026: Apple ships iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, pulling 26.6 beta security onto public builds, 38 CVE identifiers.
- June 30, 2026: Commerce lifts the export controls after an 18-day halt; Fable 5 access starts to return on July 1.
- July 27, 2026: iOS 26.6 and iPadOS 26.6 ship with 86 CVEs, 28 days after 26.5.2.
- August 17, 2026: iOS 26.6.1 and iPadOS 26.6.1 ship with 29 CVEs, and Apple’s notes say the update delivers fixes first made available in iOS 27 betas.
- September 8, 2026: iOS 26.6.2 ships as build 23G90, replacing 26.6.1’s 23G83, with no published CVE entries and a fix for software updates over cellular.
August 17 is the copy of June 29, pointed at the next train. Safari 26.6.1 followed on August 18 for macOS Sonoma and Sequoia, and its notes say those WebKit fixes first appeared in the macOS Golden Gate 27 beta. OpenAI Codex Security is on that list too, including CVE-2026-65338, credited to Amy Burnett. Meta Red Team X is on iOS 26.6.1’s Audio bug, CVE-2026-65339, a reminder that other firms’ red teams are in the same queue.
The iOS 26 security release cadence on the Mac Admins SOFA tracker is the clean version of that summer: 38 CVEs on June 29, 86 on July 27, 29 on August 17, then a zero-CVE maintenance build on September 8. Gaps of 28, 21, and 22 days. That is not Apple’s old habit of parking security in the next x.6 feature drop. It is a roughly three-week clock with a backport sentence at the top of the notes.
Glasswing’s Ledger Still Shows a Human Bottleneck
Apple is a launch partner in Anthropic’s Project Glasswing, the invite-only program built around Claude Mythos Preview. Anthropic kept Mythos off the public API, citing its skill at finding and exploiting software bugs, and handed usage to a group of about 50 firms that also includes Microsoft, Google, Amazon Web Services, Cisco, Nvidia, Broadcom, and the Linux Foundation, backed by $100 million in model credits.
Finding is no longer the scarce step. Clearing a finding still is. Patrick Garrity at VulnCheck, reading Anthropic’s public ledger in September, counted 26,153 Mythos findings since Glasswing started in April. Only 2,736, or 10.5 percent, had reached the disclosure ledger. 202, or 0.8 percent, were marked fixed, across 113 projects. Another 245 had been withdrawn.
GLASSWING’S FIVE-MONTH RECEIPTS
- Total findings: 26,153 Mythos reports logged since April 2026, per VulnCheck’s pass over the public ledger.
- Reached the ledger: 2,736 items, 10.5 percent of the pile, either disclosed to a maintainer or in that process.
- Actually patched: 202 fixed items, 0.8 percent of findings, or about 1.79 fixed bugs per project among the 113 that landed a fix.
- Still waiting: 2,096 disclosed but not confirmed fixed, plus 191 sitting in pre-disclosure.
Those Glasswing disclosure ledger receipts are the second-order problem Apple’s June note does not name. Models now spray candidate bugs at a rate no vendor’s human review queue was built for, and a share of those candidates are noise, including reports against code that is not there. Apple can ship 26.5.2 in a day once a fix exists. It cannot staff a verifier for every model-written ticket at the same speed.
The Commerce halt sits on the same calendar. Fable 5 and Mythos 5 went public around June 9, came down on June 12, and stayed dark for most users until June 30. Apple’s early iOS patch landed on day 17 of that blackout. The US government was trying to keep Mythos-class tools away from the wrong hands at the same moment Apple was treating those tools as a reason to stop leaving beta fixes on the table.
MDM Queues Now Move on a Three-Week Clock
Adam Boynton, senior enterprise strategy manager at Jamf, put the vendor problem in one line: the same AI that helps researchers find flaws helps attackers exploit them faster, so the edge goes to whoever deploys the fix first. For a phone that is a consumer device, that means Settings, General, Software Update. For a fleet, it means a staging ring, a VPN check, and a required-by date that used to have a month of slack.
26.5.2 never went to external testers before the public switch, so accessibility groups and MDM shops saw the bits at the same time as everyone else. The next morning the CVEs were public, which is the other half of Apple’s new clock: once the notes are up, waiting becomes a choice to run a documented bug. Kernel and WebKit issues are exactly the class that turns a delayed fleet into a browsing target.
Older hardware is on a slower hose. iPhone 11 is the floor for iOS 26. On June 29 there was no matching iOS 18 bulletin for the phones that cannot make that jump. The catch-up for iPhone XS, iPhone XS Max, iPhone XR, and 7th-generation iPad was iOS 18.7.10 and iPadOS 18.7.10, dated August 17, the same day as 26.6.1.
On September 8, 2026, Apple shipped iOS 26.6.2 as build 23G90, with no published CVE entries and a fix that lets a phone download a software update over cellular. That is a maintenance release, and it sat on top of a summer in which 26.5.2 and 26.6.1 had already taught the next beta’s security notes to land in the current public OS first.
Frequently Asked Questions
Which iPhones and iPads Can Install iOS 26.5.2?
Apple lists iPhone 11 and later, 12.9-inch iPad Pro (3rd generation) and later, 11-inch iPad Pro (1st generation) and later, iPad Air (3rd generation) and later, iPad (8th generation) and later, and iPad mini (5th generation) and later. Phones older than iPhone 11 stay on the iOS 18 line and did not receive this bulletin.
Did iOS 26.5.2 Get a Public Beta First?
No. The 26.5.2 and iPadOS 26.5.2 builds were not sent to Apple’s external tester group before the June 29 public release, so there was no outside accessibility or MDM dry run on that specific build. Testers had been on the 26.6 betas, which is where the security fixes first appeared.
Did Older Macs Get the Same WebKit Fixes?
Yes, through Safari 26.5.2, which Apple published the same day for macOS Sonoma and macOS Sequoia. Those Macs do not run Tahoe 26.5.2, so the browser update is how the WebKit and WebRTC fixes reach them. Safari 26.6.1 later repeated that pattern with Golden Gate 27 beta fixes on August 18.
When Did iOS 18 Get a Matching Security Drop?
Not on June 29. Apple’s security-release index shows no iOS 18 CVE bulletin that day. The next listed catch-up for iPhone XS, iPhone XS Max, iPhone XR, and 7th-generation iPad is iOS 18.7.10 and iPadOS 18.7.10, dated August 17, 2026, the same date as iOS 26.6.1.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
