Originally published at: https://tidbits.com/2026/08/17/apple-backpatches-beta-security-fixes-into-macos-26-6-2-ios-ipados-26-6-1-and-ios-ipados-18-7-10/
Apple has released four security updates to bring several of its supported operating systems into sync with current OS 27 betas and other previous releases. In each case, the company introduces the release notes with a sentence along the lines of “This update delivers security fixes that were first made available in the macOS Golden Gate 27 beta.” The updates include:
- macOS 26.6.2 Tahoe: Fresh off the macOS 26.6.1 update that addressed a Screen Sharing vulnerability, macOS 26.6.2 fixes 29 vulnerabilities.
- iOS 26.6.1 and iPadOS 26.6.1: Because iOS and iPadOS didn’t need the macOS Screen Sharing fix, their version number lags behind macOS by one. Nevertheless, iOS 26.6.1 and iPadOS 26.6.1 address 30 vulnerabilities, nearly all of which overlap with the macOS fixes. iOS 26.6.1 addresses one vulnerability not found in macOS 26.6.2: a Telephony flaw that could allow a privileged network attacker to bypass IPsec authentication and intercept traffic.
- iOS 18.7.10 and iPadOS 18.7.10: In “OS 26.6 Delivers Massive Number of Security Fixes” (27 July 2026), I predicted we’d see these 18.7.10 releases, and indeed, they incorporate the fixes from both 26.6 and 26.6.1, addressing 129 vulnerabilities in devices restricted to iOS 18 or iPadOS 18.
- visionOS 26.6.1: Apple says, “Details coming soon,” and provides no link. I haven’t heard of any real attack aimed at visionOS—the installed base may not yet justify the effort for attackers.
Apple doesn’t identify any of the vulnerabilities as having been exploited in the wild, so you can wait a few days before installing these updates to make sure they don’t come with unexpected side effects. That said, given the number of kernel and WebKit fixes, you should update soon.
What’s most notable about these updates is the number of vulnerabilities that may have been discovered with AI assistance. Nine WebKit vulnerabilities are credited to “OpenAI Codex Security – Amy Burnett,” and another is credited to “Dung Do (@_piers2) of Calif.io,” a security firm that leverages AI heavily. Combined with the AI-credited discoveries in the earlier OS 26.6 releases—including vulnerabilities found with Anthropic’s Claude and the Chinese GLM model—it’s clear that AI-assisted security research is becoming a growing source of vulnerability reports.
I suspect Apple will soon bring older versions of macOS into sync as well, with releases of macOS 15.7.10 Sequoia and macOS 14.8.10 Sonoma, along with Safari 26.6.2, which would carry all the WebKit fixes. We’ll see!