Apple released iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 with security fixes for supported iPhone, iPad, and Mac devices. The updates are available through the standard software update mechanisms, including over-the-air installation on mobile devices and System Settings > Software Update on Macs, and Apple described them as minor releases focused on security.
The Canadian Centre for Cyber Security said Apple’s advisories cover vulnerabilities affecting iOS and iPadOS versions prior to 26.5.2 and macOS Tahoe versions prior to 26.5.2. Neither Apple’s release notes nor the cited reports disclosed specific CVE identifiers or exploitation details, but the Cyber Centre urged users and administrators to review Apple’s security documentation and apply the updates promptly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
In Apple’s June 29, 2026 security advisory for iOS and iPadOS 26.5.2, Apple credited Milad Nasr and Nicholas Carlini with Claude at Anthropic for reporting CVE-2026-43715, a WebKit use-after-free flaw that could allow malicious web content to cause memory corruption. Apple said the issue was fixed through improved memory management.
In Apple’s June 29, 2026 security content for iOS and iPadOS 26.5.2, Apple credited OpenAI Codex Security with reporting three WebKit flaws: CVE-2026-43707, CVE-2026-43716, and CVE-2026-43745. The issues were described as a type confusion leading to memory corruption and two out-of-bounds flaws that could crash Safari.
Reuters, as cited by MacRumors, reported that Apple released iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 earlier than planned, pulling more than 25 security fixes forward from the 26.6 update cycle. Apple reportedly made the move out of concern that artificial intelligence could speed development of malicious hacking tools, while saying it had no evidence the patched flaws were actively exploited.
Apple released Safari 26.5.2 for macOS 15 Sequoia and macOS 14 Sonoma as part of its 26.5.2 security updates. The update primarily addressed WebKit vulnerabilities, and the report said Apple did not indicate any of the flaws had been exploited in the wild.
Apple published security advisories covering vulnerabilities affecting iOS and iPadOS versions prior to 26.5.2 and macOS Tahoe versions prior to 26.5.2. The Canadian Centre for Cyber Security urged users and administrators to review the advisories and apply the updates.
Apple released macOS Tahoe 26.5.2 as a small update to the macOS Tahoe operating system and said the release includes security fixes for Mac devices.
Apple released iOS 26.5.2 and iPadOS 26.5.2 as minor updates for its mobile operating systems, stating that they include security fixes for iPhone and iPad devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcethecyberexpress.com
Open sourceisc.sans.edu
Open sourceghacks.net
Open sourcemacrumors.com
Open sourcetidbits.com
Open sourcemacrumors.com
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.