Technology

Apple addresses a number of WebKit vulnerabilities


Apple has addressed shut to twenty vulnerabilities within the open supply WebKit browser engine that underpins its Safari browser, that are current in its desktop and pocket book, and cellular working techniques.

The updates, which take Safari to model 26.6.1 in macOS Sonoma and macOS Sequoia, macOS Tahoe to model 26.6.2, and iOS and iPad OS to variations 18.7.10 and 26.6.1 respectively, had been all launched over the previous couple of days.

In widespread with most different software program suppliers, the updates mark a big uptick within the quantity of points contained in Apple’s safety fixes, and in response to Cupertino, 9 of them are attributed to a researcher utilizing OpenAI Codex Safety – a analysis preview that connects to GitHub to assist groups determine coding flaws – a transparent demonstration of how synthetic intelligence (AI) is upending the world of vulnerability discovery.

Left alone, the problems could result in a number of disagreeable outcomes, together with browser and course of termination, reminiscence corruption, and crashes. In a single occasion, a flaw tracked as CVE-2026-64778 in WebKit Historical past could trigger a person lured to a maliciously crafted web site to inadvertently leak delicate information.

As is customary, Apple remained largely tight-lipped about whether or not or not any of the failings have been exploited within the wild, however WebKit flaws are sometimes highly-favoured by menace actors, as Adam Boynton, senior enterprise technique supervisor at Jamf, defined.

“[WebKit is] one of many largest assault surfaces on the [Apple] platform. Reminiscence corruption doesn’t imply distant code execution, however these have change into browser exploit chains prior to now,” he defined.

Nevertheless, added Boynton, the amount of WebKit flaws within the newest replace might not be essentially the most noteworthy factor about it – the standout repair in his view is CVE-2026-65346, an integer overflow in ImageIO, a framework that allows purposes to learn and write picture information.

“Exploiting it may permit an attacker to jot down reminiscence the place they shouldn’t and acquire code execution. Picture parsing flaws have traditionally been the supply mechanism for zero-click spy ware focusing on executives and different high-value people,” stated Boynton.

Additionally price immediate consideration is CVE-2026-65329, a telephony problem affecting iPhones which may allow an attacker with community privileges to bypass IPSec authentication and listen in on community visitors.

Kev catalogue

In the meantime, the US Cybersecurity and Infrastructure Safety Company (Cisa) has added one other Apple flaw – CVE-2026-65400 – to its Identified Exploited Vulnerabilities (Kev) catalogue of points deemed of great danger to the federal authorities.

CVE-2026-65400 was addressed by Apple earlier this month. It’s one other improper authentication vulnerability that might permit a menace actor with a longtime presence on the goal community to authenticate to the goal machine’s Display screen Sharing function with out legitimate credentials,.

In line with the Dutch Nationwide Cyber Safety Centre – NCSC-NL – it has been used in opposition to a number of techniques upon which port 5900 was uncovered to the general public web to acquire root entry and set up a Monero crypto miner.

As CVE-2026-65400 allows root entry, a menace actor may additionally use it as a part of a wider assault to ascertain persistence, steal credentials and information, and deploy different malware, though on the time of writing there seems to be no indication that it has been utilized in any ransomware assaults.

Below an inside directive, US authorities companies are obligated to remediate CVE-2026-65400 by Friday 21 August – its inclusion on the often up to date Kev checklist is a sign that personal sector CISOs must also take steps to remediate it in the event that they haven’t already.