Apple (AAPL) Patches About 200 Flaws in iOS 27 Release
Apple Inc. (NASDAQ: AAPL) patched roughly 200 security vulnerabilities across its September releases, in what security researchers have described as a record set of fixes for the company.
iOS 27 and iPadOS 27 carry approximately 126 fixes, about 20 of them in the kernel. macOS Golden Gate 27 resolves 210 vulnerabilities, roughly 100 of which overlap with the iOS release. The patches touch more than 90 platform components, including AppleKeyStore, Authentication Services, Foundation, Safe Browsing, Sandbox, Security, TCC and WebKit.
The kernel flaws are the ones that matter. Apple's advisories describe outcomes including memory corruption, privilege escalation, unexpected system termination and information leaks. Among the individual fixes is one that could allow a malicious application to gain root access, and another enabling remote code execution over Bluetooth.
Users who are not moving to the new release are covered separately. Apple issued iOS 26.7 and iPadOS 26.7 with more than 80 fixes, 75 of them shared with iOS 27, alongside macOS Tahoe 26.7 with 153 unique CVEs and macOS Sequoia 15.8 with more than 150 patches. tvOS 27, watchOS 27 and visionOS 27 each carry dozens of fixes, with six in Safari 27.
In one case Apple removed the affected code rather than repairing it. CVE-2026-64752, a memory corruption flaw in the CoreMedia framework that Jamf described as exploitable through a malicious image, was handled by deletion.
Apple has not indicated that any of the flaws were exploited before patching. Three of the fixes were credited to Anthropic's Claude, with OpenAI Codex Security named in Apple's additional recognition section.
