What Happened

Apple has released iOS 26.5, iPadOS 26.5, and updates across its entire OS lineup patching over 60 security vulnerabilities. The most severe is CVE-2026-28819, a kernel-level Wi-Fi remote code execution flaw — an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.

The updates span iOS 26.5, iPadOS 26.5, iOS 18.7.9, iPadOS 18.7.9, macOS Tahoe 26.5, macOS Sequoia 15.7.7, and macOS Sonoma 14.8.7. Beyond the Wi-Fi kernel RCE, the update addresses multiple WebKit vulnerabilities, additional kernel issues, and flaws across various system components. Apple extended patches back to older iOS versions, ensuring even iPhone 6s-era devices receive critical fixes.

The Center for Internet Security (CIS) issued an advisory rating multiple vulnerabilities in the update as allowing arbitrary code execution, recommending immediate patching for all Apple device users.

Sources

📰 MacRumors — iOS 26.5 Security Fixes

📰 Apple Security Releases

📰 CIS Advisory — Multiple Vulnerabilities in Apple Products

Why This Matters

Kernel-level Wi-Fi RCE is about as bad as it gets for mobile security. A vulnerability at this level means a malicious app — or potentially a crafted Wi-Fi packet — could gain full control of the device’s kernel, bypassing all sandboxing and security boundaries. This is the kind of bug that intelligence agencies pay millions for.

The breadth of the update (60+ fixes across every Apple platform) also highlights how the attack surface of modern operating systems continues to expand. Credit to Apple for backporting patches to older devices, but the sheer volume of critical fixes in a single release suggests the industry-wide effect of AI-assisted vulnerability discovery — likely Anthropic’s Project Glasswing partners — is already accelerating patch cycles. If you have an Apple device, update now.

By Allan