2 min read

iOS 26.6 closes 78 vulnerabilities

Apple’s iOS 26.6 closes 78 vulnerabilities tied to 87 CVEs and prepares Spotlight for the coming iOS 27 update.

Image: ITzine

Apple’s iOS 26.6 update closes 78 vulnerabilities tied to 87 CVE identifiers, while also laying groundwork for iOS 27. The release prepares Spotlight for a major indexing transition and adds smaller changes to contact blocking and device theft protection.

iOS 26.6 prepares Spotlight for iOS 27

Much of the update’s most consequential work is hidden under the hood. Apple is adjusting Spotlight so iPhones do not launch into a lengthy reindexing process after iOS 27 arrives this autumn.

Based on beta testing and findings in insider builds, Apple is expected to modify both system search and Siri. On some devices, indexing reportedly stretched for days or even a week, suggesting the next release could create significant background workloads. iOS 26.6 appears to move part of that processing ahead of time, while users are still on the current branch.

Recommended reading

Claude Cowork sandbox escape exposed 500,000 Macs

For users, the intended result is straightforward: iPhones should remain more responsive after the autumn update, with searches returning content without extended pauses while the database is rebuilt.

New warnings and security fixes

The update now warns users when they reach the blocked-contacts limit. Instead of simply refusing another entry, iOS displays “Blocked Contacts Limit Reached” and asks the user to remove an existing contact before adding a new number.

Code also contains signs of a feature that could automatically lock an unlocked iPhone if it is suddenly snatched from someone’s hand. The feature is not included in the final iOS 26.6 build, but its presence suggests Apple is testing additional protections for street theft.

Apple also fixed an issue affecting managed corporate devices and private Wi-Fi addresses. In one scenario, the DisableAssociationMACRandomization key did not prevent users from manually switching between the Fixed and Rotating modes.

The security fixes cover components including MediaRemote, AVEVideoEncoder, Game Center, libc, and the Wi-Fi module. Potential consequences included:

  • MediaRemote: an app could obtain root privileges.
  • AVEVideoEncoder: arbitrary code could run with kernel privileges.
  • Game Center and libc: code could escape the sandbox.
  • Wi-Fi: a nearby attacker could corrupt process memory.

Apple has not said that any of the vulnerabilities were exploited before the fixes became available. It has nevertheless closed a broad set of possible entry points, making iOS 26.6 an update iPhone users should not postpone.

Source: Kod

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via ITzine

/ Keep reading