Apple
iOS 26.6 and iPadOS 26.6
128066 Jul 27, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/128066. 86 CVE entries, 12 additional recognitions. Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Draft — review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/128066
Are you credited here?
Sign in and claim your line — it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
217 lines
Showing 151–170 of 170 matching · page 4 of 4 · clear filters
CVE-2026-64730
BR2026-0000-000796
WebKit
unclaimed
Visiting a website that frames malicious content may lead to UI spoofing
Credited as Kagami Rosylight of Mozilla
CVE-2026-64783
BR2026-0000-000797
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as 杉山 壮太
CVE-2026-64783
BR2026-0000-000798
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as lattice
CVE-2026-64783
BR2026-0000-000799
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Behzad Najjarpour Jabbari (@_G4ru_)
CVE-2026-64783
BR2026-0000-000800
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Junyeong Lee
CVE-2026-64783
BR2026-0000-000801
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Mooth.ai
CVE-2026-64783
BR2026-0000-000802
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-64783
BR2026-0000-000803
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Using GLM From Z.AI
CVE-2026-64783
BR2026-0000-000804
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Gia Bui (@yabeow) from Calif.io
CVE-2026-64757
BR2026-0000-000805
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Milad Nasr
CVE-2026-64757
BR2026-0000-000806
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Nicholas Carlini with Claude
CVE-2026-64757
BR2026-0000-000807
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Anthropic
CVE-2026-43804
BR2026-0000-000808
WebKit
unclaimed
Visiting a website may lead to an app denial-of-service
Credited as Heiko Kiesel of SEEMOO
CVE-2026-43804
BR2026-0000-000809
WebKit
unclaimed
Visiting a website may lead to an app denial-of-service
Credited as TU Darmstadt
CVE-2026-43821
BR2026-0000-000810
WebKit
unclaimed
An app may be able to read files outside of its sandbox
Credited as Brian Carpenter
CVE-2026-64718
BR2026-0000-000811
WebKit Canvas
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-64719
BR2026-0000-000812
WebRTC
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Shaheen Fazim
CVE-2026-64726
BR2026-0000-000813
Wi-Fi
unclaimed
An attacker in physical proximity may be able to corrupt process memory
Credited as Mathis Mansière
CVE-2026-64726
BR2026-0000-000814
Wi-Fi
unclaimed
An attacker in physical proximity may be able to corrupt process memory
Credited as Peter Malone
CVE-2026-64755
BR2026-0000-000815
WorkoutKit
unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace