Skip to main content
Cybersecurity News Kinetic Potential

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

Apple on Monday announced patches for a record number of vulnerabilities across its desktop and mobile operating systems, including more than 200 flaws patched with the latest major releases: iOS 27 and macOS Golden Gate 27.

iOS 27 and iPadOS 27 include fixes for about 126 security flaws, 20 of which affect the kernel.

macOS Golden Gate 27 addresses 210 vulnerabilities, roughly 100 of which are shared with the iOS 27 release.

macOS Tahoe 26.7 patches 153 unique CVEs, including 26 security defects in the kernel that could lead to memory corruption, privilege escalation, system termination, and information leaks.

While the vast majority of the issues were discovered in 2026, the macOS update also fixes CVE-2022-3437, a medium-severity heap-based buffer overflow in Samba (within Heimdal) that could lead to denial-of-service (DoS) attacks.

Approximately 100 of the resolved security defects affect both the mobile and desktop operating systems. The fixes target more than 90 platform components, including AppleKeyStore, Authentication Services, Foundation, Safe Browsing, Sandbox, Security, TCC, and WebKit.

According to Jamf senior enterprise strategy manager Adam Boynton, one of the iOS bugs that stands out is CVE-2026-64752, a memory corruption issue in the media processing framework CoreMedia.

“An attacker could compromise an iPhone by getting a malicious image in front of the user. Interestingly, rather than patching the flawed code, Apple chose to remove it entirely,” Boynton said.

On Monday, Apple also rolled out iOS 26.7 and iPadOS 26.7 with patches for over 80 vulnerabilities (including approximately 70 resolved in iOS 27 and iPadOS 27), and macOS Sequoia 15.8 with over 150 patches (more than 140 also found in macOS Tahoe 26.7).

Additionally, the company released tvOS 27, watchOS 27, and visionOS 27 with patches for dozens of security flaws each, Safari 27 with six fixes, and Xcode 27 with one patch.

Apple makes no mention of any of these security defects being exploited in the wild. Users are advised to update their devices as soon as possible.

Additional information is available on Apple’s security releases page.

“The number of fixes in iOS 27 matters less than where they sit, and this is a kernel release rather than a browser release. For enterprises, the question is the same every September: how long does it take a fix Apple shipped on day one to reach every device that touches corporate data? That gap used to be a constraint and is now a choice, because same-day support means an estate can be current in hours rather than weeks,” Boynton said.

This article was published by Security Week. Please check their website for the original content.

Add new comment

Plain text

  • No HTML tags allowed.
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.
CAPTCHA This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
13 + 0 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.