Security & Threat Intelligence · 25.07.2026, 15:29 UTC
June 2026 Apple Updates, (Tue, Jun 30th)
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | SANS Internet Storm Center ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-39868, CVE-2026-43676, CVE-2026-43700, CVE-2026-43701, CVE-2026-43703. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time.
Most of the vulnerabilities affect the web browser (WebKit, libxslt, WebRTC, and Web Extension). Only four of the vulnerabilities are not directly related to web content: Three Kernel issues and one vulnerability in the IOGPUFamily.
None of the vulnerabilities is labeled as "exploited".
iOS 26.5.2 and iPadOS 26.5.2 macOS Tahoe 26.5.2 Safari 26.5.2 CVE-2026-39868: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel x x CVE-2026-43676: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit x x x CVE-2026-43700: Processing maliciously crafted web content may disclose sensitive user information. Affects WebKit x x x CVE-2026-43701: A malicious website may be able to process restricted web content outside the sandbox. Affects WebKit x x x CVE-2026-43703: Processing maliciously crafted web content may lead to an unexpected process crash. Affects libxslt x x CVE-2026-43704: A malicious web extension may be able to cause an unexpected process crash. Affects Web Extensions x x x CVE-2026-43705: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit x x x CVE-2026-43706: Processing maliciously crafted web content may lead to an unexpected …