Macworld Apple Patches Record 261 Vulnerabilities in Latest OS Updates
Article Content
- •Apple's latest updates fixed a record 261 vulnerabilities across its operating systems.
- •iOS 27 addresses 122 vulnerabilities, while macOS 27 includes 204 fixes.
- •No vulnerabilities were reported as actively exploited at the time of the updates.
On September 14, 2026, Apple released updates for iOS 27 and macOS 27, addressing a total of 261 vulnerabilities, the highest number ever patched in a single release. iOS 27 alone fixed 122 vulnerabilities, while macOS 27 included 204 fixes. Notably, 75 of the vulnerabilities were shared between iOS 27 and the concurrent iOS 26.7 update, which also fixed over 80 issues. The vulnerabilities include critical kernel flaws that could allow remote code execution and unauthorized access. Despite the large number of patches, none of the vulnerabilities were reported as actively exploited. The updates were influenced by advancements in AI coding tools that have improved vulnerability detection. Users have reported issues with downloading iOS 27, with some seeing iOS 26.7 instead. Security-relevant applications also require updates for compatibility with macOS 27. The updates reflect an ongoing trend of increasing vulnerability disclosures as AI tools become more prevalent in security research.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…