Isc.Sans.Edu Apple Releases Critical Security Updates for Legacy Devices
Article Content
- •Apple patched 84 vulnerabilities across multiple legacy operating systems.
- •Critical flaws include issues in WebKit, kernel access, and Wi-Fi systems.
- •No vulnerabilities are currently known to be exploited in the wild.
On May 11, 2026, Apple issued critical security updates for older iPhones, iPads, and Macs, addressing 84 vulnerabilities across various operating systems. The updates include fixes for serious flaws related to WebKit, kernel access, Wi-Fi, and sandbox escapes. Devices affected include those running macOS Tahoe, Sequoia, and Sonoma, as well as iOS and iPadOS versions 15 through 18. Notably, the updates patch vulnerabilities that could allow arbitrary code execution and privilege escalation. Apple confirmed that none of the patched vulnerabilities are currently exploited in the wild. The updates are essential for maintaining device security, especially for legacy systems that continue to receive support. Apple emphasizes the importance of updating to mitigate potential risks associated with these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2025-43524 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…