Official source evidencesupport.apple.comVersioned article
Official source article · support.apple.com

About the security content of iOS 26.2 and iPadOS 26.2 - Apple Support

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 20:28 UTC
Linked CVEs39

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2025-43529Apple Multiple Products Use-After-Free WebKit Vulnerability
  • CVE-2025-14174Google Chromium Out of Bounds Memory Access Vulnerability
  • CVE-2025-9086Out of bounds read for cookie path
  • CVE-2025-5918Libarchive: reading past eof may be triggered for piped file streams
  • CVE-2025-43511A use-after-free issue was addressed with improved memory management
  • CVE-2025-46311An inconsistent user interface issue was addressed with improved state management
  • CVE-2025-46304The issue was addressed with improved bounds checks
  • CVE-2025-43518A logic issue was addressed with improved checks
  • CVE-2025-43534A user with physical access to an iOS device may be able to bypass Activation Lock
  • CVE-2025-43538A logging issue was addressed with improved data redaction
  • CVE-2025-43539The issue was addressed with improved bounds checks
  • CVE-2025-46279A permissions issue was addressed with additional restrictions
  • CVE-2025-43542This issue was addressed with improved state management
  • CVE-2025-43535The issue was addressed with improved memory handling
  • CVE-2025-46301The issue was addressed with improved bounds checks
  • CVE-2025-46287An attacker may be able to spoof their FaceTime caller ID
  • CVE-2025-43532A memory corruption issue was addressed with improved bounds checking
  • CVE-2025-43533The issue was addressed with improved bounds checks
  • CVE-2025-46290A remote attacker may be able to cause a denial-of-service
  • CVE-2025-46286A logic issue was addressed with improved validation
  • CVE-2025-46300The issue was addressed with improved bounds checks
  • CVE-2025-46285An integer overflow was addressed by adopting 64-bit timestamps
  • CVE-2025-46303The issue was addressed with improved bounds checks
  • CVE-2025-43475A logging issue was addressed with improved data redaction
  • CVE-2025-46288A permissions issue was addressed with additional restrictions
  • CVE-2025-43531A race condition was addressed with improved state handling
  • CVE-2025-46302The issue was addressed with improved bounds checks
  • CVE-2025-46292This issue was addressed with additional entitlement checks
  • CVE-2025-43536A use-after-free issue was addressed with improved memory management
  • CVE-2025-46276An information disclosure issue was addressed with improved privacy controls
  • CVE-2025-46299A memory initialization issue was addressed with improved memory handling
  • CVE-2025-43428A configuration issue was addressed with additional restrictions
  • CVE-2025-46305The issue was addressed with improved bounds checks
  • CVE-2025-43541A type confusion issue was addressed with improved state handling
  • CVE-2025-43501A buffer overflow issue was addressed with improved memory handling
  • CVE-2025-46277A logging issue was addressed with improved data redaction
  • CVE-2025-46298The issue was addressed with improved memory handling
  • CVE-2025-43537A path handling issue was addressed with improved validation
  • CVE-2024-7264ASN.1 date parser overread

Source and provenance

Original title: About the security content of iOS 26.2 and iPadOS 26.2 - Apple Support. Captured 28 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗