Tech News

iOS 27 and macOS Golden Gate 27: Apple Fixes Over 200 Security Flaws, Including 20 in the iPhone Kernel

Apple has released the new major versions of its operating systems: macOS Golden Gate 27, iOS 27, and more. These new releases include numerous security fixes. In fact, 210 vulnerabilities were patched in macOS Golden Gate 27 and around 126 in iOS 27, with about a hundred of them shared between the two systems. Here’s what we know about this wave of fixes, available since Monday, September 14, 2026.

Let’s start with a reminder: as I wrote in June after WWDC, macOS 27 Golden Gate marks the end of major updates for Intel Macs. Since September 14, 2026, this version has been available, alongside iOS 27, iPadOS 27, tvOS 27, watchOS 27, visionOS 27, Safari 27, and Xcode 27.

And as every year, Apple’s back-to-school update comes with security fixes, and this time there are really a lot of them. The good news is that there isn’t a single zero-day flaw, but some vulnerabilities are worth discussing. However, the analysis is not straightforward because Apple does not provide severity levels or even CVSS scores for the disclosed vulnerabilities.

iOS 27: 20 Flaws in the Kernel Alone

126 is the number of security flaws patched in iOS 27, and among them, 20 vulnerabilities directly affect the kernel. Some involve memory corruption, while others involve privilege escalation. Here are the ones I’m highlighting:

  • CVE-2026-64752, CoreMedia. Processing a malicious image can lead to arbitrary code execution. Apple says it removed the vulnerable code. "An attacker could compromise an iPhone simply by getting a malicious image in front of the user. Interestingly, rather than fixing the flawed code, Apple chose to remove it entirely", explains Adam Boynton, Enterprise Strategy Manager at Jamf (comments reported by SecurityWeek).
  • CVE-2026-65414, Bluetooth. A remote attacker could execute arbitrary code.
  • CVE-2026-65329, Telephony. An attacker positioned on the network could bypass IPSec authentication and intercept traffic.
  • CVE-2026-43674, Wi-Fi. With physical access to an unlocked device, it was possible to view Wi-Fi passwords without authentication.

macOS Golden Gate 27: Screen Sharing, SMB, and CUPS

On the Mac side, the macOS Golden Gate 27 bulletin is even more extensive, and several flaws affect network services widely used in enterprise environments.

  • CVE-2026-65400, Screen Sharing Server. An attacker on the network could authenticate to the screen sharing service without valid credentials. For a service that is often enabled on remotely manageable Macs, this is a serious flaw.
  • CVE-2026-84568, autofs. An attacker controlling a network directory server could execute arbitrary code with root privileges.
  • SMB and WebDAV. Nine CVEs for the SMB client, four for WebDAV. Simply connecting to a malicious server can sometimes corrupt kernel memory (CVE-2026-84515) or execute code (CVE-2026-65374).
  • CUPS. Nine flaws in the printing system, including two that grant root privileges to an application and one remotely exploitable flaw for code execution (CVE-2026-43692).
  • Gatekeeper. Six separate bypasses, spread across autofs, copyfile, the kernel, System Settings, and WebDAV.

And here’s a small detail that confirms the current trend: 8 security flaws mentioned in the macOS 27 bulletin credit Calif.io "in collaboration with Claude and Anthropic Research". In other words, AI-assisted vulnerability discovery is taking hold at Apple (there were already 11 in July 2026).

What About Intel Macs?

Golden Gate 27 installs only on Apple Silicon Macs, including the MacBook Neo 2026. Intel Macs will at best remain on macOS Tahoe, which also received an update in version 26.7 (it fixes more than 150 security flaws). Meanwhile, macOS Sequoia 15.8 also includes more than 150 fixes, while iOS 26.7 and iPadOS 26.7 also get more than 80 vulnerability fixes.

For further reading, here is the list of security bulletins published by Apple on September 14, 2026:

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.