Enterprise & Industry

Apple rushes iOS 26.5.2 patch for 29 bugs as AI supercharges hackers

Zero-days not yet exploited, but AI threats force Apple to ship early updates.

Deep Dive

On Monday, Apple pushed out version 26.5.2 for iOS, iPadOS, and MacOS, addressing 29 security vulnerabilities. The majority target WebKit, Apple's browser engine—which isn't limited to Safari but powers web content in many third-party iOS apps—making these bugs accessible via any link you tap. While none of the flaws have been publicly exploited yet, Apple decided to ship the patches ahead of their planned inclusion in the 26.6 feature update (expected early July).

The move is a direct response to the rise of AI-powered cyberattacks. Apple told Reuters that attackers are using generative AI to accelerate malware development and exploit discovery, compressing the time between vulnerability disclosure and weaponization. Traditionally, companies bundle security fixes into major OS updates, but that buffer has eroded. As Jamf's Adam Boynton noted, “Bundling fixes into big feature releases worked when you had weeks before a flaw got exploited, and that buffer is gone.” Users are urged to update immediately via Settings > General > Software Update.

Key Points
  • Apple released OS version 26.5.2 patching 29 security flaws (most in WebKit).
  • Updates were pulled forward from the planned 26.6 release due to heightened AI-driven attack risks.
  • No zero-days exploited yet, but WebKit bugs could allow malware or data theft through any app that loads web content.

Why It Matters

AI is compressing the security patch cycle, forcing Apple—and likely others—to ship fixes faster than ever.

📬 Get the top 10 AI stories daily