isc.sans.edu 14 Sept 2026, 18:33 UTC

Apple Patches Record 261 Flaws Across New Operating Systems

Apple Patches Record 261 Flaws Across New Operating Systems

APPLE released its annual operating-system updates on 14 September 2026, including iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27 and visionOS 27. It also issued bug-fix-only updates for the 26-series systems and macOS Sequoia 15.8. According to SANS Internet Storm Centre, the releases address 261 vulnerabilities, reportedly Apple’s largest patch set to date. Apple has not assigned individual severity ratings, and none of the issues is marked as exploited.

The vulnerabilities affect a wide range of components and devices. Reported impacts include arbitrary code execution, root or kernel-level privileges, sandbox escapes, Gatekeeper bypasses, sensitive-data exposure, memory corruption and denial of service.

Examples include CVE-2026-84506, which could allow arbitrary code execution with kernel privileges through udf; CVE-2026-84607, involving a sandboxed app executing code with kernel privileges through AVEVideoEncoder; CVE-2026-65400, which could allow network attackers to authenticate to Screen Sharing without valid credentials; and CVE-2026-64752, which could permit arbitrary code execution when processing a malicious image.

The article also reports user difficulties downloading iOS 27, with some devices displaying iOS 26.7 even when iOS 27 may have installed. Users upgrading macOS should check compatibility updates for security tools: Little Snitch reportedly requires a recent update, while Objective-See’s BlockBlock was updated to version 2.5.2.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline