Safari 26.6.1 Fixes 22 WebKit Bugs for Older Macs on Sonoma and Sequoia

Apple released Safari 26.6.1 on August 18, closing 22 security holes in WebKit for Mac owners who are still running macOS Sonoma or macOS Sequoia instead of the newest Tahoe release. The update is listed on Apple's own security releases page with a release date of 18 Aug 2026, dated for macOS Sonoma and macOS Sequoia specifically.
That distinction matters. Apple's Mac point updates like the recent macOS Tahoe patches only reach machines already upgraded to Tahoe. Anyone who has stayed on Sonoma or Sequoia, whether by choice or because older hardware cannot run Tahoe, gets security coverage exclusively through standalone Safari updates like this one.
What the 22 fixes cover
All 22 vulnerabilities patched in this release sit inside WebKit, the rendering engine Safari uses to display web pages. Two of them are described as capable of triggering memory corruption, the more serious category of browser bug that can potentially let an attacker run unwanted code. The remaining 20 address crashes and issues that could leak data while browsing.
None of the flaws have been reported as actively exploited. That puts this release in the routine-maintenance category rather than an emergency patch, but the volume of fixes in a single point release is still substantial for a browser-only update.
An unusual number of AI-found bugs
One detail stands out in the credits: OpenAI's Codex Security team is listed as a reporting source nine separate times across the 22 CVEs, meaning roughly four in ten of the flaws fixed here were surfaced with the help of an AI code-analysis tool rather than a traditional human security researcher. It is a small but visible sign of how vulnerability hunting in browser engines is starting to shift toward automated tooling.
Who should install it and how
- macOS Sonoma users get Safari 26.6.1 through Software Update.
- macOS Sequoia users get the same Safari 26.6.1 build.
- macOS Tahoe users are unaffected by this specific release — Tahoe already carries the equivalent WebKit fixes through macOS 26.6.2, which shipped a day earlier on August 17.
To install it, open System Settings > General > Software Update on a Sonoma or Sequoia Mac. Safari updates on older macOS versions install independently of the operating system itself, so there is no separate OS version bump to look for — just the Safari version number under About Safari.
Part of a busy patch week
This is the third Apple security release in three days. Apple shipped iOS 26.6.1 and macOS 26.6.2 on August 17 for devices running the current major OS versions, and the macOS Screen Sharing flaw that CISA rated a critical 9.8 severity was already being fixed out-of-cycle before that. Safari 26.6.1 fills the remaining gap for Mac owners who have not moved to Tahoe, making sure WebKit's memory-corruption fixes reach them even without a full OS update.
Because all of this traces back to the same WebKit codebase, the practical takeaway is simple: whichever macOS version your Mac is running, check Software Update this week, since between the OS point releases and this Safari update, nearly every actively supported Mac now has a fix waiting.
Frequently Asked Questions
What does Safari 26.6.1 fix?
Safari 26.6.1 fixes 22 security vulnerabilities in WebKit, the engine Safari uses to render web pages. Two of the flaws could lead to memory corruption, while the other 20 address crashes and potential data-leakage issues triggered by malicious web content.
Who needs to install Safari 26.6.1?
It applies to Mac owners running macOS Sonoma or macOS Sequoia. Macs already updated to macOS Tahoe get the equivalent WebKit fixes through the macOS 26.6.2 system update instead, so they do not need this separate Safari release.
How do I install Safari 26.6.1?
Go to System Settings, then General, then Software Update on a Mac running Sonoma or Sequoia. The update installs through the normal software update mechanism even though only Safari's version number changes.
Is Safari 26.6.1 an emergency patch?
No. Apple has not reported any of the 22 fixed vulnerabilities as actively exploited, which places this release in routine security maintenance rather than an urgent out-of-cycle fix.
Why were AI tools credited for finding these bugs?
OpenAI's Codex Security is listed as the reporting source for 9 of the 22 CVEs fixed in this release, roughly 40 percent of the total. It reflects a broader shift toward automated code analysis tools being used to find vulnerabilities in large codebases like WebKit.





