Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Apple addresses multiple WebKit vulnerabilities | Computer Weekly

By Computer Weekly by By Computer Weekly
August 18, 2026
Home Uncategorized
Share on FacebookShare on Twitter


Apple has addressed close to 20 vulnerabilities in the open source WebKit browser engine that underpins its Safari browser, which are present in its desktop and notebook, and mobile operating systems.

The updates, which take Safari to version 26.6.1 in macOS Sonoma and macOS Sequoia, macOS Tahoe to version 26.6.2, and iOS and iPad OS to versions 18.7.10 and 26.6.1 respectively, were all released over the past couple of days.

In common with most other software suppliers, the updates mark a significant uptick in the volume of issues contained in Apple’s security fixes, and according to Cupertino, nine of them are attributed to a researcher using OpenAI Codex Security – a research preview that connects to GitHub to help teams identify coding flaws – a clear demonstration of how artificial intelligence (AI) is upending the world of vulnerability discovery.

Left alone, the issues may lead to multiple unpleasant outcomes, including browser and process termination, memory corruption, and crashes. In one instance, a flaw tracked as CVE-2026-64778 in WebKit History may cause a user lured to a maliciously crafted website to inadvertently leak sensitive data.

As is customary, Apple remained largely tight-lipped about whether or not any of the flaws have been exploited in the wild, but WebKit flaws are typically highly-favoured by threat actors, as Adam Boynton, senior enterprise strategy manager at Jamf, explained.

“[WebKit is] one of the largest attack surfaces on the [Apple] platform. Memory corruption doesn’t mean remote code execution, but these have become browser exploit chains in the past,” he explained.

However, added Boynton, the volume of WebKit flaws in the latest update may not be the most noteworthy thing about it – the standout fix in his view is CVE-2026-65346, an integer overflow in ImageIO, a framework that enables applications to read and write image files.

“Exploiting it could allow an attacker to write memory where they shouldn’t and gain code execution. Image parsing flaws have historically been the delivery mechanism for zero-click spyware targeting executives and other high-value individuals,” said Boynton.

Also worth prompt attention is CVE-2026-65329, a telephony issue affecting iPhones which could enable an attacker with network privileges to bypass IPSec authentication and snoop on network traffic.

Kev catalogue

Meanwhile, the US Cybersecurity and Infrastructure Security Agency (Cisa) has added another Apple flaw – CVE-2026-65400 – to its Known Exploited Vulnerabilities (Kev) catalogue of issues deemed of significant risk to the federal government.

CVE-2026-65400 was addressed by Apple earlier this month. It is another improper authentication vulnerability that could allow a threat actor with an established presence on the target network to authenticate to the target device’s Screen Sharing feature without valid credentials,.

According to the Dutch National Cyber Security Centre – NCSC-NL – it has been used against multiple systems upon which port 5900 was exposed to the public internet to obtain root access and install a Monero crypto miner.

As CVE-2026-65400 enables root access, a threat actor could also use it as part of a wider attack to establish persistence, steal credentials and data, and deploy other malware, although at the time of writing there appears to be no indication that it has been used in any ransomware attacks.

Under an internal directive, US government agencies are obligated to remediate CVE-2026-65400 by Friday 21 August – its inclusion on the regularly updated Kev list is an indication that private sector CISOs should also take steps to remediate it if they have not already.



Source link

By Computer Weekly

By Computer Weekly

Next Post

/C O R R E C T I O N -- Breezeline/

Recommended.

NetEase Announces First Quarter 2025 Unaudited Financial Results

NetEase Announces First Quarter 2025 Unaudited Financial Results

May 15, 2025
Cyber governance practices are maturing – and reshaping leadership expectations | Computer Weekly

Cyber governance practices are maturing – and reshaping leadership expectations | Computer Weekly

July 30, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio