Older iPhones got 122 security flaws fixed in a single update
On 17 August 2026 Apple shipped four security updates: iOS and iPadOS 26.6.1, iOS and iPadOS 18.7.10, macOS Tahoe 26.6.2 and visionOS 26.6.1. The update for the older line stands apart. Where the current systems receive around 30 fixes each, 18.7.10 fixes 122 vulnerabilities, and it applies to only four hardware models. Apple states no totals of its own, and the figures here were counted from the CVE identifiers on Apple's own pages. None of those pages says that any of the vulnerabilities has been exploited in attacks.
What happens technically
The two current systems share almost everything. The detail page for iOS and iPadOS 26.6.1 lists 29 unique CVE identifiers across 21 entries and eight components, with WebKit the heaviest at eleven entries. macOS Tahoe 26.6.2 lists 28, and they are the same vulnerabilities with one exception. That exception is a flaw in Telephony, CVE-2026-65329, where an attacker in a privileged network position can bypass IPSec authentication and eavesdrop on traffic. Apple describes it as an authentication issue addressed with improved state management, and the entry applies to iPhone only. The heaviest single flaw by Apple's own impact description is CVE-2026-65346 in ImageIO, an integer overflow where processing an image may lead to arbitrary code execution. That is the classic surface where the victim needs to do nothing beyond receiving something.
The update for the older line is a different story altogether. iOS and iPadOS 18.7.10 covers iPhone XS, iPhone XS Max, iPhone XR and the seventh generation iPad, four models in total, and fixes 122 unique CVE identifiers across 97 entries and 44 components. WebKit accounts for 21 of the entries and the kernel for 15. Among the heaviest are CVE-2026-64747 in AVEVideoEncoder, where an app may execute arbitrary code with kernel privileges, and CVE-2026-43723 in MediaRemote, where an app may gain root privileges. Only 19 of the 122 also appear in the update for the current systems. The explanation is that the new fixes have gone into the 26 line continuously, while the older line receives them in one batch. Apple states that the fixes first shipped in beta versions of forthcoming systems. For visionOS 26.6.1 there is nothing to read yet: the update appears in the overview with a date but without a detail page, and Apple writes that details are coming.
What this means for you if you still run old hardware
The number 122 is not a measure of how poor those older phones are. It is a measure of how much accumulates once a device falls outside the main line. If you have iPhone XS, XS Max, XR or the seventh generation iPad in service, this is the largest single update of the four, and it is not optional. Our assessment is that such devices rarely appear in the risk register, precisely because they work. A phone that makes calls and reads email does not look like a problem until somebody asks which system version it runs.
It is also worth looking at what is no longer possible. Those four models do not receive the 26 line, and therefore cannot receive features and hardening that exist only there. The question is then no longer whether they are updated, but how long you intend to keep them in service and for what. If you are responsible for phones used for multi-factor sign-in, those particular devices deserve a retirement date rather than merely an update routine. If your organisation is covered by NIS2, an overview of which models and system versions are actually in use is a precondition for saying anything at all about vulnerability management on mobile.
Berigo recommends
- Install 18.7.10 on iPhone XS, XS Max, XR and the seventh generation iPad now. This is the largest of the four updates, and it covers the oldest devices.
- Do not read the absence of known exploitation as an absence of urgency. The fixes are public, and so are the descriptions of the flaws.
- Obtain a list of which iPhone and iPad models are actually in use, and which system line each of them sits on.
- Set a retirement date for models that no longer receive the latest system line, especially those used for multi-factor sign-in.
- Hold off on any conclusion about visionOS 26.6.1 until Apple publishes the details, and install the update while you wait.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch