Apple published multiple security release notes and update entries across its platforms, including iOS/iPadOS point releases (e.g., iOS/iPadOS 26.2.1, 18.7.4, 16.7.13, 15.8.6, 12.5.8) and watchOS 26.2.1, with Apple indicating no published CVE entries for several of the January 2026 point updates. Apple also refreshed or republished detailed historical security-content pages for older products, including macOS Big Sur 11.7.9 (listing fixes such as CVE-2023-34425 kernel-privilege arbitrary code execution in Apple Neural Engine, CVE-2023-32364 sandbox restriction bypass, and other privacy/logic issues), Xcode 14.1 (including multiple git issues such as CVE-2022-29187, CVE-2022-39253, CVE-2022-39260, plus an Xcode Server privilege issue CVE-2022-42797), and visionOS 2 for Apple Vision Pro (including issues like CVE-2024-44126 heap corruption from crafted files, CVE-2024-27876 arbitrary file write via archive unpacking race condition, and additional sandbox/data-access weaknesses).
Separately, a vendor blog post warned that critical WebKit vulnerabilities could enable remote compromise of iOS devices via a malicious webpage (arbitrary code execution and potential credential/data theft), emphasizing patch latency as a key risk; however, the post does not clearly map its claims to specific Apple CVEs or to the “no published CVE entries” iOS/iPadOS point releases listed on Apple’s security releases page. A Reddit /r/netsec item about a one-click vulnerability in IDIS Cloud Manager (ICM) Viewer (triggered by clicking an untrusted link) is unrelated to Apple/WebKit and does not align with the Apple security-release content.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Apple’s security releases listing shows continued patch releases across iOS, iPadOS, macOS, watchOS, tvOS, visionOS, Safari, and Xcode through January 2026. On January 26, 2026, Apple issued several iOS/iPadOS and watchOS point releases, some explicitly noting that no CVE entries were published.
A security warning reported that critical WebKit vulnerabilities could let attackers compromise iPhone and iPad devices through a malicious webpage, potentially enabling arbitrary code execution, credential theft, or access to sensitive data. The report emphasized that slow patch adoption increases exposure.
Apple later updated the visionOS 2 security advisory with additional entries or revisions. The support page indicates subsequent additions on October 28, 2024 and March 3, 2025.
Apple released security information for visionOS 2, detailing multiple vulnerabilities affecting Apple Vision Pro. The fixes covered issues such as heap corruption, arbitrary file overwrite, root-level system file modification, sandbox escapes, denial of service, VPN traffic leakage, Bluetooth access problems, and several WebKit web-origin and XSS-related flaws.
In the macOS Big Sur 11.7.9 security content, Apple said it was aware of reports that CVE-2023-41990 in FontParser and CVE-2023-38606 in the kernel may have been actively exploited against iOS versions released before iOS 15.7.1. This indicated real-world attacker interest in those bug classes.
Apple released macOS Big Sur 11.7.9 with fixes for numerous vulnerabilities across the kernel, AppSandbox, CFNetwork, and bundled third-party components such as curl, OpenSSH, SQLite, Vim, and tcpdump. The update addressed issues including privacy leaks, sandbox escapes, privilege escalation, denial of service, and arbitrary code execution.
Apple published security content for Xcode 14.1, including fixes for multiple Git vulnerabilities by updating to Git 2.32.3 and an Xcode Server privilege-escalation flaw. The Git issues could expose sensitive information from malicious repositories or enable app termination or code execution in some configurations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
zimperium.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.