Apple Releases iOS 27 and macOS Golden Gate 27 with Over 200 Vulnerability Fixes
Apple has issued major updates for its operating systems, patching approximately 200 security vulnerabilities across iOS 27, iPadOS 27, and macOS Golden Gate 27.

Apple has rolled out significant security updates for its flagship operating systems, releasing iOS 27 and macOS Golden Gate 27 to address a substantial number of vulnerabilities. The updates collectively patch approximately 200 security flaws, with iOS 27 and iPadOS 27 alone fixing around 126 issues, including 20 critical kernel vulnerabilities. macOS Golden Gate 27 addresses an even larger set of 210 vulnerabilities, with roughly 100 of these overlapping with the mobile OS fixes.
Beyond the latest major releases, Apple also provided security patches for older versions. macOS Tahoe 26.7 received fixes for 153 unique CVEs, including 26 kernel defects that could lead to memory corruption, privilege escalation, system termination, and information leaks. Notably, the macOS update also includes a patch for CVE-2022-3437, a medium-severity heap-based buffer overflow in Samba, which could be exploited for denial-of-service attacks.
The extensive list of patched vulnerabilities spans over 90 platform components, impacting critical areas such as AppleKeyStore, Authentication Services, Foundation, Safe Browsing, Sandbox, Security, TCC, and WebKit. One particularly noteworthy vulnerability, CVE-2026-64752, was identified in the CoreMedia framework. This memory corruption flaw could allow an attacker to compromise an iPhone by presenting a malicious image to the user. In an unusual move, Apple opted to remove the affected code entirely rather than simply patching the flawed component.
In addition to the primary iOS and macOS updates, Apple also released iOS 26.7 and iPadOS 26.7 with over 80 vulnerability patches, and macOS Sequoia 15.8 with more than 150 fixes. Further updates were provided for tvOS 27, watchOS 27, and visionOS 27, each containing dozens of security patches. The Safari browser also received six fixes, and Xcode 27 was updated with a single security patch.
While Apple has not indicated that any of these newly patched vulnerabilities have been exploited in the wild, users are strongly urged to update their devices to the latest versions as soon as possible to protect against potential threats. Comprehensive details on all resolved security issues are available on Apple's official security releases page.
Security experts highlight the importance of these kernel-level fixes. Adam Boynton, senior enterprise strategy manager at Jamf, commented on the significance of these updates for enterprise environments. He emphasized that the speed at which organizations can deploy these patches to all devices is crucial for maintaining security posture, especially when sensitive corporate data is involved. The ability to update devices within hours rather than weeks is now a key consideration for IT departments managing Apple fleets.
The sheer volume of vulnerabilities patched in this release underscores the ongoing challenges in securing complex operating systems. While the exact nature of all 200+ flaws varies, the inclusion of kernel-level issues and memory corruption bugs indicates a broad range of potential attack vectors that have now been closed. This proactive patching by Apple aims to maintain the integrity and security of its vast ecosystem of devices and users.
This release serves as a reminder for all users, from individual consumers to large enterprises, to prioritize software updates. Keeping devices up-to-date is one of the most effective defenses against the ever-evolving landscape of cyber threats, ensuring that known vulnerabilities are not left open for exploitation.