Apple released iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 on June 29, 2026 — a trio of security-only updates that patch more than 25 vulnerabilities across iPhones, iPads, and Macs. A standalone Safari 26.5.2 update was also released for older macOS versions. As reported by MacRumors and Macworld, the updates carry no new features and were released as emergency security patches.
Key Takeaways
- iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 were released June 29, 2026
- The updates fix 25+ security vulnerabilities, with the majority targeting WebKit (Apple's browser engine)
- Additional kernel-level fixes address six more vulnerabilities in system components
- None of the vulnerabilities are known to have been actively exploited in the wild
- No new features — these are pure security patches derived from iOS 26.6 beta work
- Update via Settings > General > Software Update on iPhone/iPad, or System Settings on Mac
What Was Fixed
Apple's security support documents confirm that the 26.5.2 updates include vulnerability fixes that were previously addressed in the iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6 developer betas. Apple has back-ported those fixes into a standalone security release ahead of the full 26.6 launch.
Breakdown of the patches, according to MacRumors and Macworld:
- WebKit (23 fixes): Vulnerabilities that "could lead to crashes or data leaks" across Safari and all in-app web views on iOS, iPadOS, and macOS
- Kernel and system components (6 additional fixes): Lower-level vulnerabilities in the operating system core
As of publication, Apple's security notes state that none of the patched vulnerabilities were known to be actively exploited. However, MacRumors notes that once Apple publishes vulnerability details publicly, malicious actors can use the information to craft exploits targeting devices that have not yet updated.
Why WebKit Vulnerabilities Are Treated as High Priority
WebKit handles all web rendering on Apple platforms. Unlike Android, where third-party browsers can use their own engines, every browser and web view on iPhone and iPad — including Chrome, Firefox, and DuckDuckGo — runs on WebKit under the hood.
A WebKit flaw can be exploited simply by visiting a malicious website, making it one of the most dangerous vulnerability classes on Apple devices. Even without known active exploitation, Apple issues these emergency patches because the exposure window between patch publication and potential exploitation is narrow.
What Came Before: The iOS 26.5.x Timeline
This latest point release follows a sequence of 26.5 updates:
- iOS 26.5 — the main incremental feature release
- iOS 26.5.1 — released approximately one month before 26.5.2; fixed a charging issue specific to the iPhone Air and iPhone 17 models
- iOS 26.5.2 — the current release; pure security patch, no new features
This pattern reflects Apple's standard security cadence: minor (.x.1) releases address device-specific bugs, while (.x.2) releases often deliver security hardening derived from ongoing beta work.
What's Coming Next
Apple is actively developing iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6, with a second public beta released on June 16, 2026. These will be the last major point releases before iOS 27 launches this fall alongside the iPhone 18 lineup, including the recently previewed iPhone 18 Fold.
How to Update Your Device
- iPhone and iPad: Go to Settings → General → Software Update
- Mac: Open System Settings, then click Software Update
- Older Macs (separate Safari update): Safari 26.5.2 is also available through Software Update on supported older macOS versions
Apple strongly recommends installing the update immediately on all supported devices.
Sources: