Skip to content

Apple iOS 26.5.2, iPadOS 26.5.2, and macOS 26.5.2 Patch More Than 25 Security Vulnerabilities

Apple's iOS 26.5.2, iPadOS 26.5.2, and macOS 26.5.2 patch more than 25 WebKit and kernel security holes. No new features. Go to Settings > Software Update now.

A
Argal
Argal
3 min read
iPhone screen showing the iOS 26.5.2 software update prompt
iPhone displaying the iOS 26.5.2 software update notification screen. Image: MacRumors

Apple released iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 on June 29, 2026 — a trio of security-only updates that patch more than 25 vulnerabilities across iPhones, iPads, and Macs. A standalone Safari 26.5.2 update was also released for older macOS versions. As reported by MacRumors and Macworld, the updates carry no new features and were released as emergency security patches.

Key Takeaways

  • iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 were released June 29, 2026
  • The updates fix 25+ security vulnerabilities, with the majority targeting WebKit (Apple's browser engine)
  • Additional kernel-level fixes address six more vulnerabilities in system components
  • None of the vulnerabilities are known to have been actively exploited in the wild
  • No new features — these are pure security patches derived from iOS 26.6 beta work
  • Update via Settings > General > Software Update on iPhone/iPad, or System Settings on Mac

What Was Fixed

Apple's security support documents confirm that the 26.5.2 updates include vulnerability fixes that were previously addressed in the iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6 developer betas. Apple has back-ported those fixes into a standalone security release ahead of the full 26.6 launch.

Breakdown of the patches, according to MacRumors and Macworld:

  • WebKit (23 fixes): Vulnerabilities that "could lead to crashes or data leaks" across Safari and all in-app web views on iOS, iPadOS, and macOS
  • Kernel and system components (6 additional fixes): Lower-level vulnerabilities in the operating system core

As of publication, Apple's security notes state that none of the patched vulnerabilities were known to be actively exploited. However, MacRumors notes that once Apple publishes vulnerability details publicly, malicious actors can use the information to craft exploits targeting devices that have not yet updated.

Why WebKit Vulnerabilities Are Treated as High Priority

WebKit handles all web rendering on Apple platforms. Unlike Android, where third-party browsers can use their own engines, every browser and web view on iPhone and iPad — including Chrome, Firefox, and DuckDuckGo — runs on WebKit under the hood.

A WebKit flaw can be exploited simply by visiting a malicious website, making it one of the most dangerous vulnerability classes on Apple devices. Even without known active exploitation, Apple issues these emergency patches because the exposure window between patch publication and potential exploitation is narrow.

What Came Before: The iOS 26.5.x Timeline

This latest point release follows a sequence of 26.5 updates:

  • iOS 26.5 — the main incremental feature release
  • iOS 26.5.1 — released approximately one month before 26.5.2; fixed a charging issue specific to the iPhone Air and iPhone 17 models
  • iOS 26.5.2 — the current release; pure security patch, no new features

This pattern reflects Apple's standard security cadence: minor (.x.1) releases address device-specific bugs, while (.x.2) releases often deliver security hardening derived from ongoing beta work.

What's Coming Next

Apple is actively developing iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6, with a second public beta released on June 16, 2026. These will be the last major point releases before iOS 27 launches this fall alongside the iPhone 18 lineup, including the recently previewed iPhone 18 Fold.

How to Update Your Device

  • iPhone and iPad: Go to Settings → General → Software Update
  • Mac: Open System Settings, then click Software Update
  • Older Macs (separate Safari update): Safari 26.5.2 is also available through Software Update on supported older macOS versions

Apple strongly recommends installing the update immediately on all supported devices.

Sources:

Explore topics related to this article

A
Argal

Argal

@clurky

Clurky is a Philippine tech news site owned and run by Argal, a Philippines-born software developer based in Singapore with a Computer Science background. He covers Philippine tech, fintech, and digital services - from gadgets and AI to software and security - along with evergreen guides and explainers, all with a builder's eye for how these systems actually work. Every article is fact-checked against primary sources.

221 posts

Comments

Join the conversation

Sign in to leave a comment and reply to others.

Sign in
Loading comments...