iOS Security News

Security news specific to Apple iOS — vulnerabilities, exploitation and patches affecting iPhone and iPad.

iOS's tightly controlled app ecosystem shifts the threat model toward platform-level and zero-click vulnerabilities, some of which have been used in sophisticated targeted-surveillance campaigns. This feed tracks iOS-specific CVEs, in-the-wild exploitation and Apple's security update releases as they are reported. Because Apple centrally controls patch delivery, fixes here tend to reach the install base faster than on more fragmented platforms.

Recent iOS items

Apple now uses iPhone alerts for targets of mercenary spywarehttps://ift.tt/JjV2Yo4
@ctinow · Aug 14, 2026
Apple Warns iPhone Users in 110 Countries of Mercenary Spyware Attackshttps://gbhackers.com/apple-warns-iphone-users-in-110-countries/
@PentestingNews · Aug 14, 2026
CVE-2026-0299Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on mac…
@cveNotify · Aug 13, 2026
CVE-2026-0298An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a…
@cveNotify · Aug 13, 2026
CVE-2026-0295A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.The GlobalProtect ap…
@cveNotify · Aug 13, 2026
CVE-2026-17431PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for.to_pdf reads the generated…
@cveNotify · Aug 13, 2026
CVE-2026-16770PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document.For an HTML string or file source, the constructor collects every…
@cveNotify · Aug 13, 2026
CVE-2026-0299Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on mac…
@cveNotify · Aug 13, 2026
CVE-2026-0298An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a…
@cveNotify · Aug 13, 2026
CVE-2026-0296Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify ap…
@cveNotify · Aug 13, 2026
CVE-2026-0295A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.The GlobalProtect ap…
@cveNotify · Aug 13, 2026
CVE-2026-0294A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. Th…
@cveNotify · Aug 13, 2026
CVE-2026-0293A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized ac…
@cveNotify · Aug 13, 2026
CVE-2026-0292An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequentl…
@cveNotify · Aug 13, 2026
CVE-2026-0291An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete sy…
@cveNotify · Aug 13, 2026
CVE-2026-17431PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for.to_pdf reads the generated…
@cveNotify · Aug 13, 2026
CVE-2026-16770PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document.For an HTML string or file source, the constructor collects every…
@cveNotify · Aug 13, 2026
CVE-2026-20269As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This r…
@cveNotify · Aug 12, 2026
CVE-2026-20268As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This r…
@cveNotify · Aug 12, 2026
CVE-2026-20267As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This r…
@cveNotify · Aug 12, 2026
CVE-2026-20271As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This r…
@cveNotify · Aug 12, 2026
CVE-2026-20270As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This r…
@cveNotify · Aug 12, 2026
CVE-2026-20272As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This r…
@cveNotify · Aug 12, 2026
CVE-2026-59112Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiD…
@cveNotify · Aug 10, 2026
Coruna, DarkSword iOS Exploits Proliferate Globallyhttps://ift.tt/rFmqB5Q
@ctinow · Aug 10, 2026
CVE-2026-59112Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiD…
@cveNotify · Aug 10, 2026
CVE-2026-17913Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security…
@cveNotify · Aug 10, 2026
CVE-2026-17724Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security sev…
@cveNotify · Aug 10, 2026
CVE-2026-66410Android and iOS apps ECOVACS PRO App improperly validate server certificates.Communication may be retrieved and/or altered.🎖@cveNotify
@cveNotify · Aug 10, 2026
DopamineAn iOS 15.0 - 18.7.1 / 26.0 - 26.0.1 jailbreak for A8 - A17 and M1 - M2 deviceshttps://ellekit.space/dopamine/🎖@malwr
@malwr · Aug 8, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.