Apple released watchOS 26.6 for Apple Watch Series 6 and later, patching a broad set of security vulnerabilities across WebKit, Kernel, WebRTC, SceneKit, CoreAudio, ImageIO, MediaRemote, AVEVideoEncoder, CloudAttestation, and Wi‑Fi. The update addresses impacts including denial of service, information disclosure, arbitrary code execution, sandbox escape, kernel memory corruption, root privilege gain, and code-signing bypass, with attack paths ranging from malicious apps and crafted media to hostile web content, nearby attackers, local network attackers, and malicious accessories or servers. Apple said the fixes included improved memory handling, bounds checking, input validation, authorization checks, state management, HTTPS enforcement, and removal of vulnerable code.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Apple released its watchOS 26.6 security advisory for Apple Watch Series 6 and later, disclosing a broad set of fixes across components including Kernel, WebKit, CoreAudio, ImageIO, MediaRemote, CloudAttestation, and Wi‑Fi. The advisory describes impacts ranging from denial-of-service and data exposure to sandbox escape, root privilege gain, kernel memory corruption, arbitrary code execution, and code-signing bypass.
Apple-published CVE records for several vulnerabilities affecting Safari/WebKit and other Apple platforms were published, including issues later noted as fixed in watchOS 26.6. The records cover flaws such as memory corruption, use-after-free, sandbox bypass, and clipboard hijacking across Apple product lines.
Apple updated several additional CVE records tied to vulnerabilities fixed in watchOS 26.6, including CVE-2026-39872, CVE-2026-43676, CVE-2026-43699, CVE-2026-43705, CVE-2026-43701, CVE-2026-43734, and CVE-2026-43726. The updates cover WebKit-related memory safety and sandbox issues affecting multiple Apple platforms.
Apple updated the CVE records for CVE-2026-43707 and CVE-2026-43721, reflecting the vulnerability information tied to fixes in watchOS 26.6 and other Apple releases. These records describe a malicious web content crash issue and a clipboard hijacking issue, respectively.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
11 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcesupport.apple.com
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.