Back Heise.De Urgent update: iOS 27, macOS 27 and Co. fix many vulnerabilities
The Apple updates provided on Monday evening include once again a lot of security fixes. This is shown by Apple’s freshly updated Security Updates website for iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27. In addition, older operating systems and the Safari browser were also updated. iOS 27 alone comes with more than 100 bug fixes. As has been common recently, many of these were likely found using AI. As always, only the latest systems receive all security-relevant bug fixes. Furthermore, Apple’s list only shows patched holes that were discovered by third parties; fixes that the company itself has implemented are not disclosed.
According to Apple’s information for iOS 27 and iPadOS 27, there were at least two remotely exploitable vulnerabilities in the versions. One affects the mobile radio modem (Baseband) from the iPhone 11 onwards and allowed a denial-of-service attack that could take away the devices' network connection. Worse is a bug in Bluetooth, which even allowed arbitrary code execution and app termination.
Otherwise, there are bugs in almost all important system areas that Apple addresses: From accessibility to the file system (writing to kernel memory), the App Store (privacy issue with persistent account identifier), CoreMedia (images lead to execution of malicious code), or Safari (app list can be read). Once again, various WebKit security vulnerabilities are also being fixed, which Apple is also addressing in macOS Sequoia (15) and Tahoe (26) in the form of Safari 27. There do not appear to be any known exploits for the iPhone and iPad holes; at least Apple does not mention this.
The scope of bug fixes in macOS 27 is similar to that in iOS 27. However, there are even more remotely attackable vulnerabilities here – not just the one in Bluetooth but also in the printer SDK CUPS and a total of three in the macOS kernel and in the network routine smbx. One of the kernel vulnerabilities can affect kernel memory; others lead to crashes. The CUPS problem can also execute arbitrary code. Many of the mentioned holes have also been patched – if the corresponding routines are present – in watchOS 27, visionOS 27, and tvOS 27.
In addition, Apple has also published iPadOS 26.7 and iOS 26.7, as well as macOS 26.7 (Tahoe) and macOS 15.8 (Sequoia). As mentioned, these do not contain all the fixes from the major updates to iOS 27, macOS 27, and so on – users should consider whether to update to the latest versions if their devices support the 27 versions. However, Intel Macs are excluded here.
Empfohlener redaktioneller Inhalt
Mit Ihrer Zustimmung wird hier ein externer Preisvergleich (heise Preisvergleich) geladen.
Ich bin damit einverstanden, dass mir externe Inhalte angezeigt werden. Damit können personenbezogene Daten an Drittplattformen (heise Preisvergleich) übermittelt werden. Mehr dazu in unserer Datenschutzerklärung .
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
