cognitive cybersecurity intelligence

News and Analysis

Search

Apple iOS 26.6 Fixes Flaws Enabling Kernel Code Execution, Root Access and Sandbox Escape

Apple iOS 26.6 Fixes Flaws Enabling Kernel Code Execution, Root Access and Sandbox Escape

Apple has released iOS 26.6 and iPadOS 26.6 to address a significant number of security vulnerabilities, including flaws that could allow malicious applications to execute code with kernel privileges, gain root access, or escape Apple’s app sandbox.

These updates were released on July 27, 2026, and are available for the iPhone 11 and later, along with supported iPad models.

The most critical issue involves the AVEVideoEncoder component. Tracked as CVE-2026-64747, this buffer overflow vulnerability could enable a malicious app to execute arbitrary code with kernel privileges.

Kernel-level execution is particularly dangerous because the kernel manages essential device functions, memory, hardware access, and security enforcement. Apple has resolved this issue by improving size validation.

Additionally, Apple patched numerous vulnerabilities in the iOS kernel itself. Several flaws could allow a local app to cause system crashes, corrupt kernel memory, write to kernel memory, or disclose sensitive kernel information.

Apple iOS 26.6 Vulnerability Fixes

These vulnerabilities include use-after-free bugs, out-of-bounds reads and writes, race conditions, integer overflows, and memory initialization issues. Among the notable kernel fixes is CVE-2026-28931, which could be exploited when a device connects to a malicious NFS server.

Apple stated that the flaw could lead to kernel memory corruption and addressed it through improved bounds checking. Another vulnerability, CVE-2026-43810, could allow a remote user to trigger a system crash or corrupt kernel memory.

The update also fixes CVE-2026-43723 in MediaRemote, a vulnerability that could enable an attacker to gain root privileges. Root access represents the highest level of control on an iPhone or iPad and could allow an attacker to bypass normal restrictions, access protected resources, and interfere with security mechanisms.

Apple resolved this issue by enhancing path validation. Multiple sandbox escape vulnerabilities were also addressed. CVE-2026-64740 in Game Center could allow a malicious app to break out of its sandbox due to improper handling of directory paths.

Apple fixed this issue with stronger path validation. In a separate case, CVE-2026-28973 in libc could permit an app to escape its sandbox through an integer overflow flaw.

Sandboxing is a core iOS security feature that isolates each app from other apps, system files, and sensitive data, making sandbox escape vulnerabilities highly valuable to attackers, particularly when combined with flaws enabling code execution or privilege escalation.

Apple has also fixed code-execution flaws in AppleDouble, ImageIO, and SceneKit. These bugs could be triggered by maliciously crafted files, images, textures, or 3D model content.

In a real attack, such flaws could be exploited through a booby-trapped attachment, downloaded file, website content, or malicious app data.

WebKit received several security fixes as well, including issues related to memory disclosure, Safari crashes, UI spoofing, iframe sandbox policy, and out-of-sandbox file access.

Since WebKit powers Safari and web content displayed within many iOS apps, users should prioritize this update. Apple has not confirmed that any of these vulnerabilities have been exploited in the wild.

However, the combination of kernel memory issues, exposure to root access, code execution bugs, and sandbox escapes makes iOS 26.6 a crucial security release. Users are advised to install the update as soon as possible through Settings > General > Software Update.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Apple iOS 26.6 Fixes Flaws Enabling Kernel Code Execution, Root Access and Sandbox Escape appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts