Apple has released iOS 26.6 and iPadOS 26.6, patching dozens of vulnerabilities across the kernel, WebKit and other core components.
Among the fixes is CVE-2026-43810, a kernel vulnerability that Apple says could allow a remote attacker to corrupt kernel memory, alongside several WebKit patches that address browser engine flaws commonly associated with sophisticated exploit chains.
Adam Boynton, Senior Security Strategy Manager at Jamf, says CVE-2026-43810 deserves a closer look because of its remote attack potential, and explains why the latest WebKit fixes are more closely tied to sophisticated spyware than phishing.
Following are this thoughts on the subject: Nineteen of the fixes sit in the kernel, and most still require an attacker to already have code running on the device. The one worth a second look is CVE-2026-43810, where Apple notes a remote user may be able to corrupt kernel memory, because remote changes the economics of an attack chain considerably.
The WebKit fixes are easy to read as a phishing story, when they are actually something slightly different. The raw material for targeted spyware is browser engine memory corruption and those chains are expensive enough that they get pointed at specific people like senior executives, journalists, anyone whose access justifies the cost.
That’s the honest reason to update promptly rather than eventually. Most people will never be a target worth that kind of investment. But once a vulnerability is patched and documented it stops being expensive, and it filters down to attackers who could never have afforded it in the first place.
I hope you’ll help support Apple World Today by becoming a patron. Almost all our income is from Patreon support and sponsored posts. Patreon pricing ranges from $2 to $10 a month. Thanks in advance for your support.



