www.thezdi.com 7/30/2026, 3:50:56 PM · external

Apple July 2026 Patch Fixes 210 Flaws Including ImageIO Bug

Apple July 2026 Patch Fixes 210 Flaws Including ImageIO Bug
Developing story vulnerability 2 articles tracked
Apple July 2026 security update patches ImageIO flaw (CVE-2026-43818)
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Available

THE July 2026 Apple Security Update Review presents a significant increase in vulnerabilities, with Apple releasing 210 unique CVEs compared to 37 in the previous month. Major components affected include iOS/iPadOS 26.6, various macOS versions, tvOS, watchOS, visionOS, and Safari. Key vulnerabilities highlighted include:

1. **CVE-2026-43818 (ImageIO)**: Allows arbitrary code execution via maliciously crafted images, posing the highest remote-exploitation risk.

2. **CVE-2026-64747 (AVEVideoEncoder)**: Enables arbitrary code execution with kernel privileges, leading to full device compromise.

3. **CVE-2026-64767 (afpfs)**: Permits remote attackers to corrupt kernel memory, posing a serious threat.

Other significant vulnerabilities include those related to Wi-Fi and various file-parsing operations. The summary emphasizes the critical nature of these updates and encourages users to stay informed on security patches from Apple and other vendors.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline