Total CVEs273 unique
(1,038 platform
listings before
deduplication)
iOS 27 kernel20 kernel fixes
Memory corruption
Privilege escalation
Info leaks
Notable RCECVE-2026-64752
CoreMedia
Image-triggered
iPhone RCE
(code removed)
Other pathsCUPS remote RCE
SMB: 9 CVEs
6 Gatekeeper
bypasses
WebKit: 6 CVEs
ExploitedNone confirmed
in the wild
What happened
Apple released iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, macOS Sequoia 15.8, iOS and iPadOS 26.7, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27 on September 14, 2026. Across all ten advisories, 273 unique CVEs are addressed. macOS Golden Gate 27 carries the broadest coverage with 210 CVEs. iOS 27 addresses around 126 CVEs with 20 of those in the kernel, covering memory corruption, privilege escalation, and information leak classes. Standout findings include CVE-2026-64752 in CoreMedia, where a malicious image could compromise an iPhone; Apple chose to remove the affected code entirely rather than patching it. Nine CVEs in the macOS SMB client include two where simply connecting to a malicious server can corrupt kernel memory. CUPS, the printing system, has nine flaws including one remote code execution path. Six separate Gatekeeper bypass routes are addressed across autofs, copyfile, the kernel, System Settings, and WebDAV. WebKit's six CVEs include paths that could enable universal cross-site scripting and sensitive data exposure during web content processing. Apple's advisories do not flag any of the 273 as exploited in the wild. Eight vulnerability discoveries in the macOS 27 advisory credit Calif.io "in collaboration with Claude and Anthropic Research," representing one of the first documented cases of Anthropic-assisted AI research credited in Apple's official security notes.
Why it matters
No CVEs confirmed as exploited in the wild reduces the urgency relative to today's Cisco story, but the kernel-heavy nature of this release changes the calculus for enterprise fleets. Twenty iOS kernel fixes in a single release is substantial. Jamf's Adam Boynton framed this accurately to SecurityWeek: the raw CVE count matters less than where the fixes sit, and this is a kernel release rather than a browser release. An unpatched iOS 27 kernel vulnerability is a much more valuable acquisition for an advanced threat actor than an unpatched WebKit flaw, because kernel-level code execution enables the kind of deep device persistence that commercial spyware relies on. Patch the entire Apple fleet now, prioritizing managed devices in sensitive environments.
Don't miss
The eight vulnerability credits to Calif.io "in collaboration with Claude and Anthropic Research" in the macOS Golden Gate 27 notes are worth a brief note. Apple's security credits are one of the few systematic public records of who finds what. Eight credited AI-assisted discoveries in a single Apple advisory, joining eleven from July 2026, suggests that AI-assisted vulnerability research is producing discoveries that clear Apple's bar for inclusion in security advisories at a pace that is accelerating. The same dynamic is referenced in The Hacker News's sidebar today: in H1 2026, Anthropic's Mythos-class models surfaced 26,153 vulnerability candidates in open-source software, of which 421 were patched upstream. The gap between candidates surfaced and patches shipped is the current bottleneck, not the discovery rate.
Potential actions
- Update all Apple devices to iOS 27, iPadOS 27, macOS Golden Gate 27 (Apple Silicon Macs), macOS Tahoe 26.7 (Intel Macs), and corresponding watchOS, tvOS, and visionOS releases. With same-day MDM support now standard per Apple, a delayed fleet patching schedule is a policy decision, not a tooling constraint. Prioritize devices handling sensitive data in high-risk environments given the kernel-heavy nature of this release.
- Evaluate exposure to the SMB client vulnerabilities specifically if macOS devices connect to external or untrusted SMB shares. Two of the nine SMB CVEs can corrupt kernel memory on connection to a malicious server without further user interaction. Restrict macOS SMB connections to trusted internal shares as an interim control on devices that cannot immediately update.
The Sip
273 CVEs. 20 iOS kernel fixes. A CoreMedia image-triggered iPhone RCE that Apple patched by deleting the code entirely. Nine SMB CVEs, two of which corrupt kernel memory on connection. None exploited in the wild yet. This is a kernel release — prioritize the fleet update and pay attention to SMB exposure.