July 28, 2026
iOS 26.6 Shipped With 87 Security Fixes, Including Kernel and Root Bugs
Subscribe
Apple's final iOS 26 point release landed Monday with a far bigger security payload than its one-line release notes hinted: 78 fixes covering 87 CVEs, including kernel, root, and sandbox-escape bugs, none exploited in the wild. The verdict is yes, update. The two features we were watching, anti-snatch and the malicious-message warning, still are not live. WhatsApp calling also reached the web app today.
The security payload nobody expected
The read going into Monday was that iOS 26.6's security delta would be modest, because Apple had already pulled a big batch of fixes forward into iOS 26.5.2 on June 29. That was wrong.
Apple's own advisory (support.apple.com/en-us/128066, published July 27) lists 78 vulnerability entries tied to 87 unique CVE numbers. TidBITS called it "more than I have ever seen in a single release set," and attributed the volume partly to AI-assisted vulnerability hunting. 9to5Mac and MacRumors walked through the standouts, and they are not the usual grab bag:
- A MediaRemote flaw that could let an app gain root privileges.
- An AVEVideoEncoder bug that could let an app execute arbitrary code with kernel privileges.
- Game Center and libc flaws that could let a malicious app escape its sandbox.
- A CloudAttestation bug that could bypass code-signing enforcement.
- An ImageIO flaw that could execute code from a maliciously crafted image.
- Three SceneKit bugs with the same risk from crafted files.
- An Accessibility issue that could expose data through iPhone Mirroring to someone with physical access.
- A Contacts flaw that could let an app add contacts without your permission.
- A Wi-Fi bug that could let a nearby attacker corrupt process memory.
On top of that, more than a dozen kernel fixes (kernel memory corruption and disclosure, network-filter bypasses, unexpected termination) and a large WebKit batch (process memory exposure, link-history leakage, interface spoofing, iframe sandbox breaks, Safari crashes). One WebKit fix, CVE-2026-64757, is credited in Apple's advisory to "Milad Nasr and Nicholas Carlini with Claude, Anthropic," a vulnerability found with Anthropic's Claude AI. That is an unusual credit line for an iOS security drop, and it lines up with TidBITS's note that AI tooling is behind the unusually high count.
None of the 87 are flagged as exploited in the wild (TidBITS, 9to5Mac). So this is important, not emergency.
Verdict: update yes. Kernel, root, and sandbox-escape bugs make this more than a "nice to have," and the only honest reason to wait is the usual 48-hour pause for early-bug reports. If you held off yesterday expecting a thin security release, that reasoning no longer holds. Settings, General, Software Update.
What actually shipped, and the open questions resolved
The release itself went live Monday at 10:27 AM Pacific, build 23G71, and Apple's releases page (support.apple.com/en-us/100100) now lists "the latest version of iOS and iPadOS is 26.6." Here is where the three things we were watching landed:
- Spotlight pre-index for iOS 27's Siri: shipped, as previewed. iPhones now start the on-device indexing work that iOS 27's Siri AI will search, so the week-long reindexing grind beta testers lived through should not hit everyone in September.
- Blocked contacts limit alert: shipped. When you hit the cap, iOS now tells you to remove an existing blocked contact before adding another, instead of failing silently.
- Anti-snatch auto-lock: did NOT ship. 9to5Mac confirms "the feature itself does not appear to be enabled as part of this release." The code is there, there is still no toggle, and Apple could switch it on in a future update. The open question of whether it needs an Apple Watch is still open.
- Malicious Message Detected iMessage warning: still in code, still no confirmed live sighting. BGR lists it as a feature of the update, but Apple's release notes do not mention it, 9to5Mac's post-release roundup does not list it, and no tester has triggered the live alert. The code, first spotted in beta 5 by X user @limpless_skelly, is in the build. Whether it is actually switched on is unproven. Treat any "Malicious Message Detected" pop-up you do see as worth sharing with Apple, but also be aware the mockup looks a lot like the fake Safari scam alerts, which is a real confusion risk.
Normal-user bug fixes that did land, per Apple's developer release notes and Geeky Gadgets: garbled HDR screenshots sent in Messages are fixed, corrupted sticker data that blocked sticker creation and syncing is fixed, and there are reports of a wallpaper-dimming fix and a CarPlay and Apple Music connectivity fix.
Power-user note: Apple fixed an MDM key. The DisableAssociationMACRandomization profile key now correctly stops users from switching Private Wi-Fi Address to Fixed or Rotating (9to5Mac). If you manage fleets, that one matters.
WhatsApp calling finally works in the web app
The biggest app-side news today is not from Apple. TechCrunch reports that WhatsApp now lets you make and receive audio and video calls from WhatsApp for Web, which for years only worked on the phone and native desktop apps.
The web Calls tab mirrors the phone and desktop, with call history and favorites, plus screen-sharing and reactions. Three more call upgrades shipped alongside it: you can transfer a call from one device to another without hanging up (start on web, continue on phone), there are waiting rooms for group call links (enable "Require approval to join" to screen who enters), and background noise suppression for noisy places. WhatsApp also says video calls now stream in HD from the first few seconds instead of taking a few seconds to ramp up.
This is a cross-platform rollout, but WhatsApp is one of the most-used iOS apps and the calls tab on web closes a long-standing gap for anyone who lives in a browser. Rollout is gradual.
Tracking
iOS 27 developer beta 5 is expected around August 3, two weeks after beta 4 on July 20 (GeeksChalk, Geeky Gadgets). After that the cadence tightens to roughly weekly betas, a Release Candidate near September 7, and the public release on or around September 14. If you are on the iOS 27 public beta, you will not see 26.6 in Software Update; you are already on newer code.
That’s the reading for this issue.
- iOS 26.6 Ships Today: The iMessage Attack Warning Nobody Mentioned Jul 27
- iOS 26.6 Lands Monday: What's in It, What's Not, and Whether to Update Jul 24
- iOS 27 Public Beta 2 Is Out. Here's What Changed and Whether to Update Jul 23
- iOS 27 beta 4 ships with new Siri voices and dual-battery iPhone code Jul 21
Want the next one?
Every new What Changed: iOS issue by email. One tap to unsubscribe.