Apple has put into circulation New security updates for iPhone XR, iPhone XS, and iPhone XS MaxThese updates are also for other devices in its ecosystem that no longer receive major operating system versions. They are discreet firmwares, with no visible interface changes, designed to close specific security vulnerabilities in devices still used daily in Spain and much of Europe.
The company has opted for a silent deployment, outside the usual cycle of major launcheswithout detailed release notes on the public developer website. Even so, the move confirms that models considered "legacy" continue to receive attention to security mattersThis is especially relevant for those who extend the life of their mobile phone, tablet, or Apple TV beyond a few years.
Devices that receive the new updates
The new patches were detected on Apple's servers on December 22th 2025 and are aimed at a very specific group of devices. In the mobile sector, the update reaches the iPhone XR, iPhone XS and iPhone XS Maxincluding specific variants that are still circulating in different markets. Although some models were particularly popular in countries like China, they are still common among European users. For practical recommendations, see how strengthen the security of your iPhone.
In parallel, the same security round extends to XNUMXth generation iPadBoth the Wi-Fi-only version and the one with mobile connectivity are widely used. This device is very common in homes, schools, and small businesses in Spain and other European countries, where it's used for studying, working remotely, or consuming online content. For tips on keeping it secure, see how Strengthen security on your iPad.
It is important to remember that All of these devices have been left out of the latest major iOS releases, such as the so-called full iOS 26. Instead of receiving that platform upgrade, Apple sends them specific firmwares that include security fixes They criticize and adapt them to older hardware, maintaining a reasonable level of protection without changing system generation.
Along with mobile phones and tablets, the company has also prepared an update focused on home theater and audio products. Specifically, the patch targets the Apple TV HD 4th generation (AppleTV5,3) and Original HomePod (AudioAccessory5,1), two devices that are still installed in many European living rooms as main multimedia players and smart speakers.
Versions and builds used by Apple
In the case of iPhones and seventh-generation iPads, the update corresponds to iOS 18.7.3 with build 22H217This is a build that Apple had already used in previous contexts and is now being reused as a basis to offer fixes to these models that have been left out of the main system roadmap.
The same package 22H217 is applied uniformly to both variants of the iPad 7 (Wi-Fi only and Wi-Fi + cellular), avoiding security differences between configurations. From the user's perspective, the change is entirely internal: there are no new icons, no additional menu options, and no modifications to the overall appearance of iOS.
For the living room ecosystem, Apple has prepared a firmware derived from tvOS 26.2 with build 23K54Designed specifically for the fourth-generation Apple TV HD and the original HomePod, this same build 23K54 was already distributed on December 12 for other devices compatible with tvOS 26.2 and is now adapted for older hardware to implement some of those fixes without requiring a full installation of the latest version.
In all cases we are dealing with small and very specific compilationsThese patches focus on resolving specific vulnerabilities. Due to their limited nature, they are not always immediately included in public version lists or accompanied by extensive documentation for developers, despite their importance from a security perspective.
What do these security patches fix?
Apple has not published a detailed list of the bugs fixed, so The specific vulnerabilities addressed are not officially known.However, given the type of deployment and the company's history, everything points to patches aimed at to close specific gaps in the operating system and in specific hardware components of these models.
The strategy usually consists of launching highly focused firmwares when a problem only affects a small subset of devicesInstead of creating a new general version for the entire range, a more targeted intervention is chosen, affecting only those devices where it has been confirmed that the flaw can be exploited in practice.
The fact that the lounge firmware is based on TvOS 26.2 This suggests that some of the recently implemented fixes—for example, in WebKit, the kernel, or network services—have now been rolled out to devices that cannot install the full version. Thus, an original Apple TV HD or HomePod benefits from a similar level of protection to newer models, despite still running on adapted software.
In practice, these updates do not add new features, nor do they change the appearance of iOS or tvOS, Their sole objective is to reinforce stability and protect the system against already identified exploits.This type of patch is especially relevant when it is suspected that a vulnerability could be used to execute code, escalate privileges, or access personal data without authorization.
Impact on users in Spain and Europe with iPhone XR and XS
In countries like Spain, France, Italy, or Germany, Models like the iPhone XR and iPhone XS are still very much present in everyday lifeMany users choose to use their device for several years before considering a change, whether for economic reasons, sustainability concerns, or simply because the performance is still sufficient for normal use.
For this user profile, the arrival of iOS 18.7.3 means a small boost to the terminal's lifespanAlthough the user may not notice any differences in terms of functions or design, having recent patches reduces the risk when using the mobile phone for online banking, shopping, messaging, social networks or storing sensitive documents.
In the case of XNUMXth generation iPadWidespread in educational settings, these fixes help maintain a more secure environment in classrooms and homes. Teachers and students who use tablets daily to access learning platforms or cloud services benefit from a device less susceptible to known vulnerabilities.
In the living room ecosystem, the update to the Apple TV HD and the original HomePod also has repercussions on home network securityThese are devices that remain powered on for much of the day, connected to the router and often with indirect access to other devices in the home. If left unpatched, they can become an entry point for attacks that exploit old vulnerabilities.
Apple's continued distribution of these types of firmware for older hardware reinforces the perception that There is a certain commitment to security beyond the end of major releasesFor many European users who prefer to extend the upgrade cycle, knowing that their iPhone XR, iPhone XS, or iPad 7 continue to receive occasional fixes is a relevant factor when deciding whether to keep the device a little longer.
How to check for and install updates
Although downloads are handled automatically in many cases, it is advisable Manually check for pending updates.especially when it comes to security patches that aren't announced with big on-screen messages.
On the iPhone XR, iPhone XS, iPhone XS Max, and the seventh-generation iPad, the process is the usual one in iOS: simply go to "Settings" > "General" > "Software Update" and wait for the system to check for new versions. If iOS 18.7.3 (build 22H217) is available for that specific model, it will appear as an update ready to download and install.
On the fourth-generation Apple TV HD, the route goes through the television itself, accessing the menu "Settings" > "System" > "Software Update"From there you can force the search for the firmware based on tvOS 26.2 with build 23K54 and, if pending, start the installation, which usually completes in a few minutes if the connection is stable.
In the case of the original HomePod, updates are primarily managed through the Home app on a paired iPhone or iPad. The speaker usually downloads and installs patches automatically, but you can manually check for a new version by accessing the device settings within the app. It's recommended to keep the HomePod powered on and plugged in throughout the process to avoid interruptions.
Beyond the specific path on each device, the underlying message is clear: Users of older models would do well to install these patches as soon as possible.They don't change the user experience or add flashy features, but they reduce the attack surface and help ensure that these devices remain a valid and relatively safe option for everyday use, both in Spain and the rest of Europe.