APPLE has released updates addressing more than 200 vulnerabilities across its latest desktop and mobile operating systems. iOS 27 and iPadOS 27 fix about 126 flaws, including 20 affecting the kernel, while macOS Golden Gate 27 addresses 210 vulnerabilities, around 100 of which are also present in iOS 27. macOS Tahoe 26.7 fixes 153 unique CVEs, including 26 kernel defects that could result in memory corruption, privilege escalation, system termination or information leaks.
The updates cover more than 90 components, including AppleKeyStore, Authentication Services, Foundation, Safe Browsing, Sandbox, Security, TCC and WebKit.
The releases also address CVE-2022-3437, a medium-severity heap-based buffer overflow in Samba’s Heimdal component that could enable denial-of-service attacks. Jamf’s Adam Boynton highlighted CVE-2026-64752, a memory-corruption flaw in CoreMedia that could allow an attacker to compromise an iPhone by presenting a malicious image; he said Apple removed the affected code rather than patching it.
Apple also issued iOS 26.7 and iPadOS 26.7 updates fixing more than 80 vulnerabilities, macOS Sequoia 15.8 with over 150 patches, and updates for tvOS, watchOS, visionOS, Safari and Xcode. Apple has not said that any of the flaws are being exploited in the wild. Users are advised to install the relevant updates as soon as possible.