<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Apple on CuraSec</title><link>https://curasec.metacog.co.kr/tags/apple/</link><description>Recent content in Apple on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 18 Aug 2026 11:37:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/apple/index.xml" rel="self" type="application/rss+xml"/><item><title>Apple Patches 108 Vulnerabilities in iOS, iPadOS, and macOS</title><link>https://curasec.metacog.co.kr/insights/2026-08-18-apple-patches-ios-and-macos-mon-aug-17th/</link><pubDate>Tue, 18 Aug 2026 11:37:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-18-apple-patches-ios-and-macos-mon-aug-17th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> 108 CVEs across iOS/iPadOS and macOS 26 is a large batch worth prioritizing; schedule updates for macOS developer workstations and managed iOS fleet this patch cycle — no KEV or PoC signals to force emergency action.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>iCloud Private Relay IP Leak via WebKit Proxy Bypass</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-apple-icloud-private-relay-can-expose-real-ips-through-webki/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-apple-icloud-private-relay-can-expose-real-ips-through-webki/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No CISA KEV, no PoC exploitation pressure, and Private Relay is a consumer privacy feature — no enterprise infrastructure to patch or reconfigure. Worth noting if Safari/WebKit is used in managed environments where IP privacy is a control assumption.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Apple July 2026 Patch Round: OS and Safari Updates</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-apple-patches-everything-july-2026-wed-jul-29th/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-apple-patches-everything-july-2026-wed-jul-29th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Ensure managed Apple devices and Safari are updated to the July 2026 releases; prioritize macOS 26 and Safari patches, and note that macOS 14/15 received separate coverage — audit fleet version distribution.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Apple macOS Tahoe 26.6 Security Update Released</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-about-the-security-content-of-macos-tahoe-26-6/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-about-the-security-content-of-macos-tahoe-26-6/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Apple&amp;rsquo;s security content page for macOS Tahoe 26.6 lists patched CVEs with no enrichment signals indicating active exploitation; schedule deployment of macOS 26.6 to managed endpoints and review the full CVE list for any vulnerabilities affecting shared components (e.g., WebKit, kernel) that may also surface in server or CI runner environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>