The current version of iOS is 26.6.1 (as of 17/08/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2025-43300Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
10.0 critical · over the network, without login · CISA deadline was 11 Sept 25
- CVE-2021-1871Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 17 Nov 21
- CVE-2021-1870Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 17 Nov 21
- CVE-2022-22587Apple Memory Corruption Vulnerability
9.8 critical · over the network, without login · CISA deadline was 11 Feb 22
- CVE-2021-30761Apple iOS WebKit Memory Corruption Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 17 Nov 21
- CVE-2021-30666Apple iOS WebKit Buffer Overflow Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 17 Nov 21
- CVE-2021-30762Apple iOS WebKit Use-After-Free Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 17 Nov 21
- CVE-2020-9818Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 3 May 22
- CVE-2021-30858Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 17 Nov 21
- CVE-2022-22620Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 25 Feb 22
- CVE-2016-4657Apple iOS Webkit Memory Corruption Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 14 Jun 22
- CVE-2022-32893Apple iOS and macOS Out-of-Bounds Write Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 8 Sept 22
- CVE-2022-42856Apple iOS Type Confusion Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 4 Jan 23
- CVE-2023-28206Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability
8.6 high · locally only, without login, needs user action · CISA deadline was 1 May 23
- CVE-2021-30869Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 17 Nov 21
- CVE-2019-7287Apple iOS Memory Corruption Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 13 Jun 22
- CVE-2016-4656Apple iOS Memory Corruption Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 14 Jun 22
- CVE-2021-30983Apple iOS and iPadOS Buffer Overflow Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 18 Jul 22
- CVE-2022-32894Apple iOS and macOS Out-of-Bounds Write Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 8 Sept 22
- CVE-2022-32917Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
7.8 high · locally only, with a basic account · CISA deadline was 5 Oct 22
- CVE-2022-42827Apple iOS and iPadOS Out-of-Bounds Write Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 15 Nov 22
- CVE-2021-30900Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 20 Apr 23
- CVE-2023-41061Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 2 Oct 23
- CVE-2023-41064Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 2 Oct 23
- CVE-2023-42824Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability
7.8 high · locally only, with a basic account · CISA deadline was 26 Oct 23
- CVE-2023-41974Apple iOS and iPadOS Use-After-Free Vulnerability
7.8 high · locally only, without login, needs user action · CISA deadline was 26 Mar
- CVE-2019-6223Apple iOS and macOS Group Facetime Vulnerability
7.5 high · over the network, without login · CISA deadline was 3 May 22
- CVE-2021-31010Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
7.5 high · over the network, without login · CISA deadline was 15 Sept 22
- CVE-2021-1879Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
6.1 medium · over the network, without login, needs user action · CISA deadline was 17 Nov 21
- CVE-2025-24200Apple iOS and iPadOS Incorrect Authorization Vulnerability
6.1 medium · with physical access only, without login · CISA deadline was 5 Mar 25
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellen
WID-SEC-W-2026-2872 · 25 Aug
- Apple iOS und iPadOS: Mehrere Schwachstellen
WID-SEC-W-2026-2537 · 28 Jul
- Apple iOS und iPadOS: Mehrere Schwachstellen
WID-SEC-W-2026-2134 · 30 Jun
iOS at a glance
iOS follows a fixed cadence: a new major version each autumn, point and security releases in between, and out-of-band fixes when something is actively exploited. Alongside the current line Apple keeps one older branch supplied with security updates — devices that no longer receive the current major quietly drop out of that supply.
In managed fleets the MDM drives updates: deferral windows, enforced installation, Declarative Device Management with a hard deadline. What works in practice is shipping security updates quickly and holding major upgrades for a short pilot group — the friction is almost always in VPN profiles, MDM payloads and line-of-business apps rather than the OS itself.
For inventory planning the hardware support horizon matters as much as the iOS version: devices stuck below the current major need a replacement plan before security updates for their branch run out.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 26 | 26.6.1 | supported |
| 18 | 18.7.10 | supported |
| 17 | 17.7.7 | End of Life |
| 16 | 16.7.16 | supported |
| 15 | 15.8.8 | supported |
| 14 | 14.8.1 | End of Life |
| 13 | 13.7 | End of Life |
| 12 | 12.5.8 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 26.6.1 | STABLE | 17/08/2026 | – |
| 26.6 | STABLE | 27/07/2026 | – |
| 26.5.2 | STABLE | 29/06/2026 | – |
Frequently asked questions
- What is the latest version of iOS?
- iOS 26.6.1, released 17/08/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the iOS release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new iOS updates?
- Tick iOS off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new iOS version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The subscription is free and ends with one click.
Watch iOSEmbed this badge
The badge shows the current iOS version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/ios)https://patchletter.com/badge/ios.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).