Apple
iOS 26.6.1 and iPadOS 26.6.1
148282 Aug 17, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/148282. 29 CVE entries, 3 additional recognitions. Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/148282
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
49 lines
Showing 1–49 of 49
CVE-2026-65339
BR2026-0000-006365
Audio
unclaimed
An app may be able to leak sensitive user information
Credited as Meta Red Team X - Nik Tsytsarkin
CVE-2026-65347
BR2026-0000-006366
ImageIO
unclaimed
Processing an image may lead to a denial-of-service
Credited as Geonha Lee (@leegn4a)
CVE-2026-65346
BR2026-0000-006367
ImageIO
unclaimed
Processing an image may lead to arbitrary code execution
Credited as Meta Red Team X - Nik Tsytsarkin
CVE-2026-64788
BR2026-0000-006368
IOGPUFamily
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as f00l (@PPPF00L)
CVE-2026-64788
BR2026-0000-006369
IOGPUFamily
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as 3ndy1(@_3ndy1)
CVE-2026-64788
BR2026-0000-006370
IOGPUFamily
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Minghao Lin@Y1nkoc
CVE-2026-64788
BR2026-0000-006371
IOGPUFamily
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as 云散花折
CVE-2026-64788
BR2026-0000-006372
IOGPUFamily
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Arjanit Isufi
CVE-2026-65343
BR2026-0000-006373
Kernel
unclaimed
A remote attacker may be able to cause unexpected system termination
Credited as Drinor Selmanaj (Sentry)
CVE-2026-65343
BR2026-0000-006374
Kernel
unclaimed
A remote attacker may be able to cause unexpected system termination
Credited as Surya Narayan Kushwaha
CVE-2026-65330
BR2026-0000-006375
Kernel
unclaimed
An app may be able to cause unexpected system termination or corrupt kernel memory
Credited as Bhaswanth Chigurupati
CVE-2026-65330
BR2026-0000-006376
Kernel
unclaimed
An app may be able to cause unexpected system termination or corrupt kernel memory
Credited as Billy Jheng Bing Jhong
CVE-2026-65330
BR2026-0000-006377
Kernel
unclaimed
An app may be able to cause unexpected system termination or corrupt kernel memory
Credited as Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-65329
BR2026-0000-006378
Telephony
unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Bedran Karakoc
CVE-2026-65329
BR2026-0000-006379
Telephony
unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Tobias Funke
CVE-2026-65329
BR2026-0000-006380
Telephony
unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Jacopo Clark
CVE-2026-65329
BR2026-0000-006381
Telephony
unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Katharina Kohls of Ruhr University Bochum
CVE-2026-64784
BR2026-0000-006382
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Janggoon Lee of Out of Bounds
CVE-2026-64784
BR2026-0000-006383
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OpenAI Codex Security - Amy Burnett
CVE-2026-43795
BR2026-0000-006384
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as wwwlk
CVE-2026-65338
BR2026-0000-006385
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OpenAI Codex Security - Amy Burnett
CVE-2026-65341
BR2026-0000-006386
WebKit
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Henock Habte
CVE-2026-64782
BR2026-0000-006387
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Seonwook Kim
CVE-2026-64782
BR2026-0000-006388
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Shubham Chaskar
CVE-2026-64782
BR2026-0000-006389
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as lattice
CVE-2026-64782
BR2026-0000-006390
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Josef Korbel
CVE-2026-64781
BR2026-0000-006391
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Thomas Guillem
CVE-2026-65351
BR2026-0000-006392
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Niels Hofmans
CVE-2026-65340
BR2026-0000-006393
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Claudio Bozzato
CVE-2026-65340
BR2026-0000-006394
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Francesco Benvenuto of Cisco Talos
CVE-2026-65340
BR2026-0000-006395
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Josef Korbel (Citadelo)
CVE-2026-65337
BR2026-0000-006396
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OpenAI Codex Security - Amy Burnett
CVE-2026-65336
BR2026-0000-006397
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Josef Korbel
CVE-2026-65335
BR2026-0000-006398
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OpenAI Codex Security - Amy Burnett
CVE-2026-65333
BR2026-0000-006399
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OpenAI Codex Security - Amy Burnett
CVE-2026-65332
BR2026-0000-006400
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OpenAI Codex Security - Amy Burnett
CVE-2026-65331
BR2026-0000-006401
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OpenAI Codex Security - Amy Burnett
CVE-2026-64715
BR2026-0000-006402
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected process crash
Credited as Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative
CVE-2026-64780
BR2026-0000-006403
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OpenAI Codex Security - Amy Burnett
CVE-2026-65334
BR2026-0000-006404
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OpenAI Codex Security - Amy Burnett
CVE-2026-43794
BR2026-0000-006405
WebKit
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Dung Do (@_piers2) of Calif.io
CVE-2026-64787
BR2026-0000-006406
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected process termination
Credited as 杉山 壮太
CVE-2026-64787
BR2026-0000-006407
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected process termination
Credited as Shubham Chaskar
CVE-2026-64778
BR2026-0000-006408
WebKit History
unclaimed
Visiting a maliciously crafted website may leak sensitive data
Credited as Mohit Negi
CVE-2026-64779
BR2026-0000-006409
WebKit Storage
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Shubham Chaskar
CVE-2026-64779
BR2026-0000-006410
WebKit Storage
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Tommy DeVoss from Braze Security Team (@thedawgyg)
Additional recognition
BR2026-0000-006411
Compression
unclaimed
Credited as Tommy DeVoss from Braze Security Team (@thedawgyg)
Additional recognition
BR2026-0000-006412
libcryptex
unclaimed
Credited as Ashish Kunwar
Additional recognition
BR2026-0000-006413
WebKit
unclaimed
Credited as Henock Habte