Vendor Security Posture Report Card: Apple - Q2 2026
Apple earns an Adequate security posture rating for Q2 2026. Explore 132 disclosed CVEs, the rise in WebKit fixes, patch delivery, and advisory quality.
Vendor Security Posture Report Card: Apple - Q2 2026
Reporting period: Q2 2026 (April 1 to June 30, 2026), covering iOS and iPadOS, macOS Tahoe, and Safari.
Vendor Summary
| Field | Notes |
|---|---|
| Vendor Name | Apple |
| Product Lines Covered | iOS and iPadOS 26, macOS Tahoe 26, and Safari 26 (for macOS Sonoma and Sequoia) |
| Reporting Period | Q2 2026 (April 1 to June 30, 2026) |
| Overall Posture Rating | Adequate |
| Prior Period Rating | Unavailable (first report card for this vendor) |
| Total CVEs Disclosed (Period) | 132 unique CVEs across the covered product lines, as currently listed in Apple's advisories |
| Critical and High Severity Count | Unavailable. Apple's advisories do not publish CVSS scores, and NVD scoring for the period was incomplete at the time of writing. |
| CVEs With Confirmed In-the-Wild Exploitation | 0 (no CVE from this period is listed in the KEV catalog, and no covered advisory reports exploitation) |
Rating Scale Reference
The rating scale applied consistently across every report card in this series, so that ratings remain comparable from one vendor and one period to the next:
| Rating | Criteria |
|---|---|
| Strong | Disclosure volume and severity trend stable or improving, advisories timely and complete, no unpatched critical exposure at time of writing. |
| Adequate | Posture broadly sound with isolated gaps, such as a delayed patch cycle or an incomplete advisory, that do not indicate a systemic pattern. |
| Needs Improvement | Recurring gaps across the period: repeated delayed patches, incomplete disclosures, or a rising severity trend. |
| Concerning | Evidence of a systemic issue: sustained critical exposure, exploitation preceding a patch, or a pattern of incomplete or delayed disclosure. |
This section is included in full on every post, unchanged, so the scale is never assumed to be self-evident.
Introduction
This report card assesses Apple's security posture for the second quarter of 2026 across its iOS, iPadOS, macOS, and Safari product lines. Apple receives an overall rating of Adequate. The factor most responsible is a shift in what Apple disclosed: browser-engine fixes made up half of the iOS and iPadOS disclosures this quarter, while patch delivery stayed fast and no Apple CVE from the period reached the KEV catalog.
Scope and Methodology
This assessment covers the security releases Apple published between April 1 and June 30, 2026 that carry CVE entries for the product lines below. The releases reviewed were iOS and iPadOS 26.4.2 (April 22), iOS and iPadOS 26.5 and macOS Tahoe 26.5 (May 11), Safari 26.5 (May 13), and iOS and iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 (June 29). Four point releases in the period, iOS 26.4.1, macOS Tahoe 26.4.1, iOS 26.5.1, and macOS Tahoe 26.5.1, list no published CVE entries and add nothing to the counts.
- Included: iOS and iPadOS 26, macOS Tahoe 26, and Safari 26 for macOS Sonoma and Sequoia.
- Excluded: watchOS, tvOS, visionOS, Xcode, accessory firmware, and the older operating system branches (iOS and iPadOS 15 through 18, macOS Sequoia and Sonoma). Apple also shipped security updates for several older branches on May 11; they are outside the counts here.
- Data sources: Apple's published security advisories, CVE and NVD records, and KEV catalog listings.
Data limitations. Apple's advisories list the affected component, impact, and CVE-ID but do not include CVSS scores, and NVD scoring for many of these records was incomplete at the time of writing. This post therefore does not band the period by CVSS. CVE counts were tallied by hand from the advisories as currently published and de-duplicated across platforms. Apple has revised several of these advisories since release, so counts taken at release would be lower. The comparison to the prior period covers iOS and iPadOS only.
Vulnerability Disclosure Volume and Trend
Apple's advisories for the covered product lines list 132 unique CVEs for the period. iOS and iPadOS account for 106 of them (67 in iOS 26.5, 1 in iOS 26.4.2, and 38 in iOS 26.5.2), and macOS Tahoe accounts for 125 (87 in macOS Tahoe 26.5 and 38 in macOS Tahoe 26.5.2). Most iOS and macOS fixes are shared, which is why the combined total is far lower than the sum of the platforms.
For the prior period, the iOS and iPadOS advisories for the first quarter (iOS 26.3 and iOS 26.4) list 88 unique CVEs, 44 in each. Q2 disclosure volume for iOS and iPadOS is therefore up by 18 CVEs, roughly 20 percent. The change is concentrated in one area:
- WebKit and browser-engine entries: 53 of 106 iOS and iPadOS CVEs in Q2 (50 percent), against 14 of 88 in Q1 (16 percent).
- All other components: 53 in Q2, down from 74 in Q1, a decline of about 28 percent.
The largest single contributor was the June 29 release of iOS 26.5.2 and macOS Tahoe 26.5.2. According to Apple, that update delivers fixes first made available in the 26.6 betas, and 31 of its 38 CVEs sit in WebKit, WebRTC, and related web components. The source material does not explain the spike further.
Severity Distribution Analysis
A CVSS-based breakdown into critical, high, medium, and low bands is not possible for this period, for the reasons given under Scope and Methodology. This is an explicit deviation from the template's CVSS-based severity distribution requirement. As a partial substitute, this section reads Apple's own impact statements for noteworthy entries in the covered advisories:
- Arbitrary code execution: one entry, CVE-2026-28819 in the Wi-Fi component of macOS Tahoe, described as allowing an app to execute arbitrary code with kernel privileges.
- Root privilege escalation: four entries, CVE-2026-28951 (kernel), CVE-2026-28915 (CUPS), CVE-2026-28919 (StorageKit), and CVE-2026-28976 (UserAccountUpdater).
- Gatekeeper or quarantine bypass: four entries on macOS, CVE-2026-28954, CVE-2026-28849, CVE-2026-28900, and CVE-2026-28914.
- Remote kernel memory corruption: one entry, CVE-2026-43668 in mDNSResponder.
- Everything else: the remainder are mostly process crashes, denial-of-service conditions, information disclosure, and browser policy bypasses such as Content Security Policy or same-origin issues.
Because the WebKit share of disclosures rose sharply, the distribution has tilted toward content-processing bugs, though these entries mostly describe crashes or data exposure rather than code execution. Whether the period is weighted toward higher severity than Q1 cannot be determined from vendor data alone.
Patch and Remediation Timeliness
Apple states that it does not disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. The fixes were available when the advisories were published, but the time Apple took to develop and deliver those fixes after discovery cannot be established from these advisories. The more useful observable measures are release cadence and reach.
- Release timing: security releases with CVE entries arrived on April 22, May 11, May 13 (Safari 26.5), and June 29, gaps of 19, 2, and 47 days between these dates. Apple has not published a fixed cadence commitment in the advisories reviewed, so adherence to a committed schedule cannot be assessed.
- Mid-cycle delivery: the June 29 releases brought fixes from the 26.6 betas to stable users 28 days before iOS and macOS 26.6 shipped on July 27.
- Older devices: on May 11 Apple shipped fixes for iOS and iPadOS 18.7.9, iPadOS 17.7.11, iOS 16.7.16, and iOS 15.8.8 alongside the current release, so older supported hardware received updates the same day.
- Lag cases: no case was identified in which a fix lagged significantly behind disclosure.
Exploitation and Real-World Impact
No CVE from this period appears in the KEV catalog. The nearest Apple additions fall outside the window: three on March 5 and three on March 20, both before the period, and a macOS entry added on August 18, after it. None of the covered Q2 advisories carries an Apple statement that an issue may have been exploited in an attack, and no exploitation preceding a patch was observed for the period.
The contrast with the first quarter is worth noting. Seven Apple CVEs were added to the KEV catalog in Q1, and Apple's iOS 26.3 advisory reported one actively exploited issue. Against 132 disclosures in Q2, an exploitation rate of zero is a favorable signal. It should be read with some caution, since KEV listings can be added long after a fix ships.
Advisory and Communication Quality
Apple's advisories are consistent in structure. Each entry names the component, the affected devices, the impact, a short description of the fix, and the CVE-ID, and the pages carry clear published dates and per-entry revision notes such as "Entry added" and "Entry updated". The gaps this quarter are completeness and timing:
- Ten CVEs in the covered advisories were added after the release date: nine on August 25, 2026 (for the May releases) and one on July 27, 2026 (for the June 29 releases). That is under eight percent of the period's total.
- The same practice appears in earlier advisories. iOS 26.4 (a Q1 release) had five entries added on May 11 and one on August 20, so backfilling is not confined to this quarter.
- Apple's advisories do not include CVSS scores or severity ratings, which leaves prioritization to the reader and to third-party scoring.
Notable Incidents This Period
No single incident was materially significant to this period's rating. A noteworthy kernel-privilege entry is CVE-2026-28819, the Wi-Fi kernel issue in macOS Tahoe 26.5, which was fixed in the same release that disclosed it and is not listed in the KEV catalog. A full technical analysis belongs in a dedicated post.
Historical Trend Comparison
Unavailable, as this is the first report card for Apple. The Q1 2026 figures in the volume and exploitation sections serve as the baseline for the next edition.
Risk Context for Organizations
For organizations that rely on Apple devices, the Adequate rating supports keeping their normal update rhythm rather than moving to emergency handling. Two features of the period deserve attention in planning. First, the growth in WebKit and web-component fixes means that browser-engine updates, which reach iOS, iPadOS, macOS, and Safari together, carry a larger share of the period's security value than they did in Q1. Second, the June 29 release delivered a large batch of fixes ahead of the next feature update, so fleets that wait for the numbered release will run for several weeks without them.
Organizations with older managed devices should also note that the May 11 fixes reached older branches on the same day, which makes staying on a supported branch a workable alternative where full upgrades are not yet possible. Closer monitoring of Apple's advisory revisions is reasonable, given that entries continued to be added months after release.
Overall Posture Rating and Rationale
Apple's Q2 2026 rating is . Three factors most influenced it:
- Exploitation and patch delivery: no Apple CVE from the period reached the KEV catalog, fixes were available at disclosure, and older branches were patched the same day (see Patch and Remediation Timeliness and Exploitation and Real-World Impact).
- Disclosure volume: iOS and iPadOS disclosures rose by roughly 20 percent, driven by a jump in WebKit-related entries (see Vulnerability Disclosure Volume and Trend).
- Advisory completeness: ten CVEs were added after release, and the advisories omit CVSS scores (see Advisory and Communication Quality).
The gaps are real but limited in share, and they do not amount to a systemic pattern, which is why the rating stays at Adequate rather than moving to Needs Improvement. The absence of confirmed exploitation and of identified delays between public disclosure and fix availability supports the Adequate rating, while the advisory revisions and incomplete severity scoring prevent a Strong rating.
Key Takeaways
- Apple's advisories list 132 unique CVEs for iOS, iPadOS, macOS Tahoe, and Safari in Q2 2026, and the overall rating is Adequate.
- No Apple CVE from the period is in the KEV catalog, compared with seven Apple additions in Q1.
- iOS and iPadOS disclosures rose about 20 percent over Q1, and WebKit-related entries rose from 16 percent to 50 percent of the total.
- Apple added ten CVEs to the period's advisories after release, and its advisories do not publish CVSS scores.
- Fixes shipped at disclosure, older supported branches were patched the same day, and the June 29 releases delivered 26.6 beta fixes 28 days early.
Conclusion
Apple's second quarter shows fast, broad patch delivery and no confirmed exploitation, set against a larger volume of browser-engine fixes and advisories that were still being completed months after release. These findings feed the ongoing vendor and compliance monitoring work behind this series. The Q3 2026 report card for Apple is expected after the third-quarter reporting window closes.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.




