Apple Patches (Almost) Everything Again: March 2026 Edition
Apple has released a new batch of security patches for its operating systems, covering a wide range of vulnerabilities across macOS, iOS, iPadOS, tvOS, watchOS, and visionOS. In this article, we’ll take a closer look at the patches and what they mean for users.
What’s Included in the Patches?
The patches address a total of 85 different vulnerabilities, with none of them currently being exploited. The affected systems include the last three macOS ‘generations’, as well as the last two versions of iOS and iPadOS. For tvOS, watchOS, and visionOS, only the current version received patches.
Which Systems Are Affected?
The following systems are affected by the patches:
- iOS 26.4 and iPadOS 26.4
- iOS 18.7.7 and iPadOS 18.7.7
- macOS Tahoe 26.4
- macOS Sequoia 15.7.5
- macOS Sonoma 14.8.5
- tvOS 26.4
- watchOS 26.4
- visionOS 26.4
- Safari 26.4
- Xcode 26.4
What Are the Vulnerabilities?
The patches address a wide range of vulnerabilities, including:
- CVE-2025-43376: A remote attacker may be able to view leaked DNS queries with Private Relay turned on.
- CVE-2025-43534: A user with physical access to an iOS device may be able to bypass Activation Lock.
- CVE-2026-20607: An app may be able to access protected user data.
- CVE-2026-20631: A user may be able to elevate privileges.
- CVE-2026-20632: An app may be able to access sensitive user data.
- CVE-2026-20633: An app may be able to access user-sensitive data.
- CVE-2026-20637: An app may be able to cause unexpected system termination.
- CVE-2026-20639: Processing a maliciously crafted string may lead to heap corruption.
- CVE-2026-20643: Processing maliciously crafted web content may bypass Same Origin Policy.
- CVE-2026-20651: An app may be able to access sensitive user data.
- CVE-2026-20657: Parsing a maliciously crafted file may lead to an unexpected app termination.
- CVE-2026-20660: A remote user may be able to write arbitrary files.
- CVE-2026-20665: Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
- CVE-2026-20668: An app may be able to access sensitive user data.
- CVE-2026-20684: An app may bypass Gatekeeper checks.
- CVE-2026-20687: An app may be able to cause unexpected system termination or write kernel memory.
- CVE-2026-20688: An app may be able to break out of its sandbox.
- CVE-2026-20690: Processing an audio stream in a maliciously crafted media file may terminate the process.
- CVE-2026-20691: A maliciously crafted webpage may be able to fingerprint the user.
- CVE-2026-20692: "Hide IP Address" and "Block All Remote Content" may not apply to all mail content.
- CVE-2026-20693: An attacker with root privileges may be able to delete protected system files.
- CVE-2026-20694: An app may be able to access user-sensitive data.
- CVE-2026-20695: An app may be able to determine kernel memory layout.
- CVE-2026-20697: An app may be able to access sensitive user data.
- CVE-2026-20698: An app may be able to cause unexpected system termination or corrupt kernel memory.
- CVE-2026-20699: An app may be able to access user-sensitive data.
- CVE-2026-20701: An app may be able to connect to a network share without user consent.
- CVE-2026-28816: An app may be able to delete files for which it does not have permission.
- CVE-2026-28817: A sandboxed process may be able to circumvent sandbox restrictions.
- CVE-2026-28818: An app may be able to access sensitive user data.
- CVE-2026-28820: An app may be able to access sensitive user data.
- CVE-2026-28821: An app may be able to gain elevated privileges.
- CVE-2026-28822: An attacker may be able to cause unexpected app termination.
What Should You Do?
If you’re running any of the affected systems, it’s essential to update your software as soon as possible to ensure you have the latest security patches. You can do this by going to the Settings app and checking for updates.
Remember, security is a top priority, and it’s always better to be safe than sorry. By keeping your software up to date, you can help protect yourself from potential security threats.
In conclusion, the latest batch of security patches from Apple is a significant step in ensuring the security and stability of its operating systems. By addressing a wide range of vulnerabilities, Apple is helping to protect users from potential threats and ensuring a safer computing experience.
We hope this article has provided you with a comprehensive overview of the patches and what they mean for users. If you have any questions or concerns, feel free to reach out to us in the comments below.







