Apple Patches Record 261 CVEs in iOS 27 and macOS Golden Gate 27

Apple’s September 14 update fixes 261 CVEs across eight OS trains, with 20 kernel patches in iOS 27 and 210 in macOS Golden Gate 27

C. da Costa Avatar
C. da Costa Avatar

By

Image: Security Week

Key Takeaways

Key Takeaways

  • Apple patches a record 261 CVEs across eight OS releases in one cycle.
  • Remove CVE-2026-64752 entirely; Apple eliminated flawed CoreMedia code instead of patching it.
  • Prioritize kernel-level fixes over CVE counts, as enterprise fleets face immediate risk exposure.

Apple’s September 2026 OS refresh addresses a record 261 CVEs spanning eight operating system release trains, with kernel-level fixes at the center of the update.

Apple shipped iOS 27, iPadOS 27, macOS Golden Gate 27, and five companion releases on September 14, 2026, closing what independent analysts describe as the largest single patch cycle in the company’s history.

The fixes span every major Apple platform simultaneously. The key numbers by release:

  • iOS 27 and iPadOS 27: roughly 126 CVEs patched, 20 in the kernel; components include AppleKeyStore, TCC, WebKit, Sandbox, and Authentication Services
  • macOS Golden Gate 27: 210 CVEs addressed, including sandbox escapes, root privilege escalation, and remote code execution via Bluetooth, CUPS, and WebDAV; approximately 100 fixes shared with iOS 27
  • macOS Tahoe 26.7: 153 CVEs, 26 of which are kernel defects covering memory corruption, privilege escalation, and information leaks
  • macOS Sequoia 15.8: 150-plus patches, more than 140 shared with Tahoe 26.7
  • iOS 26.7 and iPadOS 26.7: 80-plus CVEs for users not yet on iOS 27, with roughly 70 overlapping the iOS 27 fix set

One vulnerability stands out from the rest. CVE-2026-64752, a memory corruption flaw in CoreMedia, allowed an attacker to compromise an iPhone through a malicious image. Adam Boynton, Senior Enterprise Strategy Manager at Jamf, told SecurityWeek: “An attacker could compromise an iPhone by getting a malicious image in front of the user. Interestingly, rather than patching the flawed code, Apple chose to remove it entirely.”

For enterprise security teams, raw CVE counts are the wrong metric. Boynton made that point directly to SecurityWeek: “The number of fixes in iOS 27 matters less than where they sit, and this is a kernel release rather than a browser release.” With same-day MDM support now standard, delayed fleet patching is a policy decision, not a tooling problem.

None of the vulnerabilities in this cycle are flagged as exploited in the wild, according to Apple’s security notes, a finding corroborated by SANS ISC analysis. The highest verified CVSS scores in the patch set reach 7.5 (HIGH), covering CVE-2026-28930 and CVE-2026-28969. The breadth of kernel and system-level fixes means the practical risk window opens the moment CVE details are public. Update your devices now.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →