Zero Day Initiative | Blog
Follow
The July 2026 Apple Security Update Review
Apple released 210 unique CVEs across multiple operating systems and Safari in July 2026, a significant increase from the previous month. As Apple does not provide severity scores, analysis relies on the nature of the vulnerabilities. CVE-2026-43818 (ImageIO) is a critical remote arbitrary code execution vulnerability, affecting iOS and all macOS versions, making it highly exploitable. CVE-2026-64747 (AVEVideoEncoder) allows an app to execute arbitrary code with kernel privileges, affecting most Apple platforms and representing a full system compromise. CVE-2026-64767 (afpfs) enables remote, unauthenticated kernel memory corruption or system termination, though limited to macOS.Other notable vulnerabilities include CVE-2026-43776 (AppleDouble) and several SceneKit bugs, which provide file-parsing paths to arbitrary code execution. CVE-2026-43750 (Wi‑Fi) allows code execution with elevated privileges outside the sandbox. Additionally, CVE-2026-64696 (SMB) and CVE-2026-43810 (Kernel) are identified as further remote kernel-corruption bugs. The total patches include 9 code execution, 26 elevation of privilege, 11 sandbox escape, and 75 denial of service vulnerabilities. This release highlights the ongoing "bug apocalypse" impacting vendors, even Apple.