iOS Security News

Security news specific to Apple iOS — vulnerabilities, exploitation and patches affecting iPhone and iPad.

iOS's tightly controlled app ecosystem shifts the threat model toward platform-level and zero-click vulnerabilities, some of which have been used in sophisticated targeted-surveillance campaigns. This feed tracks iOS-specific CVEs, in-the-wild exploitation and Apple's security update releases as they are reported. Because Apple centrally controls patch delivery, fixes here tend to reach the install base faster than on more fragmented platforms.

Recent iOS items

CVE-2026-85704 A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/ config…
@cveNotify · Sep 4, 2026
CVE-2026-85047 Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox…
@cveNotify · Sep 4, 2026
CVE-2026-85047 Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox…
@cveNotify · Sep 3, 2026
Pegasus infected a Serbian student movement member’s iPhone through a zero-click iMessage exploit.At least 14 people in Serbia have faced advanced spyware targeting in 2026.Read: https://thehackernews…
@thehackernews · Sep 3, 2026
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone https://ift.tt/Y53tMgs
@ctinow · Sep 3, 2026
Smashing Security podcast #483: This AI helps thieves steal your iPhone https://ift.tt/F51XeHE
@ctinow · Sep 2, 2026
CVE-2026-20280 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20279 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20278 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20276 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20275 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20274 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20280 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20279 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20278 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20276 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20275 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20274 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20280 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20279 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
CVE-2026-20278 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This…
@cveNotify · Sep 2, 2026
Firefox for iPhone Adds Built-In Ad Blocker to Block Third-Party Ads and Trackers https://gbhackers.com/firefox-for-iphone-adds-built-in-ad-blocker/
@PentestingNews · Sep 2, 2026
CVE-2026-70331 Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. 🎖
@cveNotify · Sep 1, 2026
13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds https://gbhackers.com/iphone-vulnerabilities-exploited/
@PentestingNews · Sep 1, 2026
CVE-2026-81267 A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled…
@cveNotify · Aug 31, 2026
CVE-2026-43657 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to enumerate installed apps. 🎖
@cveNotify · Aug 31, 2026
CVE-2026-61792 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repositor…
@cveNotify · Aug 29, 2026
CVE-2026-70331 Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. 🎖
@cveNotify · Aug 28, 2026
CVE-2026-51376 An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache 🎖
@cveNotify · Aug 28, 2026
CVE-2026-65367 A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexp…
@cveNotify · Aug 27, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.