Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for Apple iPhone and iPad emergency security updates fixing image-processing spyware vulnerability August 2026

Apple Pushes Emergency iPhone and iPad Updates — Check Your Team’s Devices

Apple shipped iOS 26.6.1 and iOS 18.7.10 on 17 August, fixing dozens of security flaws across iPhones, iPads, and Macs. The standout fix is an image-processing bug that security experts say has all the hallmarks of a spyware delivery vector.

Update now: iOS 26.6.1 and iOS 18.7.10 fix an ImageIO flaw (CVE-2026-65346) in the same bug class used to deliver Pegasus spyware. Go to Settings > General > Software Update on every company and personal device that touches your business.

What’s the Risk

CVE-2026-65346 is an integer overflow in Apple’s ImageIO framework — the component that decodes every image your iPhone processes. An attacker who crafts a malicious image can trigger arbitrary code execution on the device. No tap required. The victim just has to receive the image via iMessage, WhatsApp, or email.

This is exactly how previous spyware campaigns like NSO Group’s Pegasus and Operation Triangulation worked — zero-click image exploits that gave attackers full device access without the owner knowing. Apple hasn’t confirmed active exploitation yet, but the bug class is a known favourite of commercial spyware vendors.

What to Do

  • Update every iPhone and iPad in your business to iOS 26.6.1 or iOS 18.7.10 today. Settings > General > Software Update.
  • Don’t forget older devices — iOS 18.7.10 covers iPhone XS, XS Max, and XR models that can’t run iOS 26.
  • If your team uses personal phones for work email or MFA, send them a message now asking them to update.
  • Consider a mobile device management (MDM) policy if you don’t have one — it lets you enforce updates across the business rather than relying on individuals to remember.

Why This Matters for Australian SMBs

Here’s what we see across our Australian client base: businesses that run tight patching on their Windows servers and laptops but treat iPhones as personal devices, even when those phones carry company email, MFA tokens, client contacts, and banking apps. A zero-click image exploit on an unpatched iPhone is a direct path to your business data — and no amount of server patching will stop it. The fix takes two minutes. The risk of ignoring it doesn’t.

Need help rolling out a mobile update policy? Our managed IT team can set up MDM so your devices stay current without you chasing staff to update.

Written by Michael Sacco, Head of Service Delivery, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors from its Brookvale base.


Not Sure Your Devices Are Up to Date?

We can check your team’s devices and set up mobile device management so updates happen automatically — no more chasing staff.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →