Apple released iOS 26.6, iPadOS 26.6, and macOS Tahoe updates, which closed 78 vulnerabilities. The list of researchers whose findings were included in the security release included two experts from the Russian company Positive Technologies (PT), which has been under US and EU sanctions since 2022.

Ilya Andr from the iOS Experts PT MAZE team is listed in the bulletin as the author of several fixed vulnerabilities in Game Center and Safari. The discovered problems could have allowed an application to access confidential user data or disrupt the authorization mechanism. Vladislav Shevchenko from the PT ESC Threat Response and Research Department is mentioned in the section on the operating system kernel.

As Andr explained, a vulnerability is often not a bug in the code, but a situation where a trusted component can be misused to bypass protection. The discovered problems are reported to Apple through the Apple Security Research platform along with a description and demonstration of exploitability. Details are not disclosed until a fix is released. The researcher noted that Apple's response speed has significantly increased: if previously it took weeks to get responses to reports, now the company responds within one to two hours.

Despite the sanctions, Apple continues to cooperate with Russian security researchers, accepting their reports and including them in updates. According to Andr, when reviewing reports, the vulnerability itself is important to the company, not the author's nationality.

Read more on the topic: