In this article
- Big Picture: what's at stake in this update
- Technical Details: WebKit, Kernel and the logic of "chains"
- Privacy Concerns: why the spyware issue appears again
- What changes for the user: fixes, features and parallel versions
- Next Steps: how to update safely and reduce risk
- What to do now (without dramatising, without delaying)
- FAQ

Big Picture: what's at stake in this update
The "update now" warning is not marketing: it's risk management. iOS 26.2 includes security fixes for critical system and browser components, and Apple confirmed that two WebKit flaws "may have been exploited" in sophisticated attacks against targeted individuals in versions prior to iOS 26. WebKit is the navigation engine that powers Safari and, in practice, influences the attack surface of any browser on iPhone, because all depend on the same system foundations. In practice, updating to iOS 26.2 reduces the likelihood of a "drive-by" attack (just visiting a malicious page) being able to execute code on the device. And when these flaws combine with other vulnerabilities, they can be part of an attack chain: a first step in the browser, followed by privilege escalation to gain deeper control of the system.Technical Details: WebKit, Kernel and the logic of "chains"
The two vulnerabilities already exploited were registered as CVE-2025-43529 and CVE-2025-14174 and are related to WebKit. The public description is deliberately limited: Apple tends to limit details to buy time while users update. Nevertheless, the typical scenario is concerning: specifically crafted web content can trigger arbitrary code execution when the user interacts with the page. In addition to the browser, iOS 26.2 fixes a flaw in the Kernel (CVE-2025-46285) that could allow an app to gain root privileges. Kernel is the "core" of the operating system: it manages memory, processes and permissions. If an attacker reaches root, they can bypass barriers like app sandboxing (the isolation that prevents one app from accessing another's data), paving the way for message reading, code capture and session hijacking — including banking. This is where the idea of attack chain comes in: flaws in WebKit can be the entry point; flaws in the Kernel can be the lift to complete control. Even if each vulnerability, in isolation, seems "difficult", the combination can drastically reduce the attacker's effort.
Privacy Concerns: why the spyware issue appears again
The update comes alongside Apple alerts about spyware campaigns hitting users in dozens of countries. Spyware, in this context, is highly targeted malware, designed for persistent surveillance: it collects information, observes usage patterns and can monitor communications, even when using end-to-end encrypted apps (encryption protects content in transit, but doesn't prevent a compromised device from reading what appears on screen). It's important to separate two ideas: (1) most people are not typical targets of mercenary spyware; (2) the flaws exploited in WebKit and Kernel remain relevant to everyone, because opportunistic exploitation tends to increase when technical details become more widely known after the patch is released. Therefore, updating to iOS 26.2 is a measure of digital hygiene, not just a response to "elite" threats. If you suspect compromise, common signs include abnormal heating, sudden performance degradation and the appearance of unrecognised apps. Restarting can temporarily interrupt some behaviours, but shouldn't be treated as a "clean-up". The aim here is to reduce the window of exposure: update to iOS 26.2 and review security habits (permissions, installed profiles, two-factor authentication and account alerts).What changes for the user: fixes, features and parallel versions
In addition to security, iOS 26.2 includes bug fixes mentioned by Apple, such as an issue with pre-release albums in Apple Music and an incorrect state in a Privacy and Security setting that could appear as "managed" by an organisation. There is also reference to improvements and new options in system features (including security alerts and adjustments to features like "Liquid Glass"), but the reason to act now remains mitigation of exploited vulnerabilities. In parallel, Apple has made iOS 18.7.3 available, which also fixes flaws (including WebKit ones). This is relevant for devices that cannot go to iOS 26. If your iPhone doesn't support the latest version, the recommended alternative is to stay on the supported line with patches — and, when available, install the equivalent update. Still, for those who can, updating to iOS 26.2 tends to be the simplest way to stay at the current security level. There is still a detail that raised questions: the absence of iOS 26.1.1 as a "quick patch". The advanced explanation involves a "Background Security Improvements" feature activated in iOS 26.1, capable of applying certain security improvements in the background. It doesn't replace a full update when there are critical fixes, but it helps reduce exposure between versions.Next Steps: how to update safely and reduce risk
The recommended procedure is simple and should be done locally: Settings > General > Software Update. Avoid installing "updates" from links received by message, and be wary of pop-ups imitating system warnings. If you manage several iPhones in the family, it's worth confirming manually on each one: relying solely on automatic updates can delay installation. For those with higher exposure (journalists, activists, executive teams, regulated areas), additional measures may make sense: enabling Lockdown Mode and reducing the attack surface (fewer profiles, fewer extensions, fewer permissions). And if you're considering changing equipment for security or reliability reasons, also confirm support policies and timelines — for example, how the warranty coverage works and what the processing timelines are in the context of support.
What to do now (without dramatising, without delaying)
If your iPhone is compatible, updating to iOS 26.2 is the most effective measure to close vulnerabilities already exploited and reduce the likelihood of infection from attack chains starting in the browser. Do the update today, restart the device and confirm that you're on the correct version. Then review sensitive permissions (Location, Microphone, Camera) and keep your apps up to date. Mobile security is rarely a "grand gesture"; it's a set of small consistent decisions. For editorial transparency, the base information in this piece was adapted from the original source: reference article. For official details and security notes, also consult Apple's support documentation. In short: updating to iOS 26.2 is not "just another update"; it's closing doors that have already been used.FAQ
- How do I know if I should update to iOS 26.2 already?
- If your iPhone is compatible and not yet on the latest version, the recommendation is to install now: iOS 26.2 fixes WebKit flaws that have already been exploited in real attacks.
- Is it safe to update from a link I received by SMS or email?
- No. The safest method is to update through the system path: Settings > General > Software Update. Links and pop-ups are often used in phishing schemes.
- What is WebKit and why do these flaws matter?
- WebKit is the navigation engine that powers Safari and influences how web content is processed on iPhone. Flaws in WebKit can allow a malicious page to execute code on the device.
- What does a Kernel flaw mean?
- The Kernel is the core of the operating system. A vulnerability in the Kernel can allow privilege escalation (for example, reaching root), breaking boundaries between apps and increasing the impact of an attack.
- I have an older iPhone. If I can't install iOS 26.2, what do I do?
- Install the latest supported version available for your device (in the source text iOS 18.7.3 is mentioned as a parallel update). The aim is to stay on a line that receives security patches.
- Do automatic updates arrive in time in these cases?
- Not always. In urgent fixes, it's prudent to check manually and install the update as soon as it's available, rather than waiting for a notice.
Get more articles like this one.
Refurbished tech analysis + €5 with BEMVINDO5 on your first order.
Refurbished tech with warranty
iPhones, MacBooks, iPads and more, tested and certified, with a 24-month warranty.
24-month warrantyShipping up to 8 business days
See products →
