Apple released an early security update for iOS 26.5.2 and iPadOS 26.5.2 on June 29, patching 29 security vulnerabilities primarily in the WebKit and Safari browser engine [1, 2, 3]. This move breaks from Apple's usual pattern of bundling security patches with major iOS releases, unless zero-day exploits are discovered [4, 2, 3]. Apple cited the rapid development of AI-powered malicious hacking tools as the impetus for accelerating its security update schedule [4, 2, 3].

None of the vulnerabilities patched in iOS 26.5.2 are confirmed zero-day exploits or known to be actively exploited, according to Apple [4, 1, 2, 3]. The security fixes included in this update previously appeared in iOS 26.6 beta versions before Monday’s official release [2].

Apple’s goal is to reduce the time between publishing fixes and end users applying them, to better mitigate the threat posed by AI-accelerated hacking attempts [4, 2, 3]. The iOS 26.5.2 update reflects this shift in policy, as past updates only delivered security patches alongside new iOS system versions unless urgent zero-day exploits were detected [4, 2, 3].

The 29 vulnerabilities addressed demonstrate particular focus on improving browser engine security, a common attack vector for exploits [1]. Apple plans to continue refining this accelerated patch schedule in response to evolving AI-enabled cybersecurity threats.