Apple patches ~200 flaws in iOS 27 and macOS Golden Gate
Apple released iOS 27 and macOS Golden Gate 27, fixing about 200 security defects across its mobile and desktop systems; roughly 100 vulnerabilities overlap between the releases.
Apple on Monday released iOS 27 and macOS Golden Gate 27, addressing roughly 200 security vulnerabilities across its mobile and desktop operating systems. About 100 of those defects affect both platforms.
iOS 27 and iPadOS 27 include fixes for approximately 126 security issues, including about 20 kernel-level flaws. macOS Golden Gate 27 resolves 210 vulnerabilities, with roughly 100 overlapping the iOS fixes. Apple also published macOS Tahoe 26.7, which patches 153 unique CVEs and includes 26 kernel-related defects that could lead to memory corruption, privilege escalation, system termination or information leaks. One older issue corrected in the macOS updates is CVE-2022-3437, a heap-based buffer overflow in Samba’s Heimdal component that could be used to cause denial-of-service conditions.
The patches touch more than 90 platform components, including AppleKeyStore, Authentication Services, Foundation, Safe Browsing, Sandbox, Security, TCC and WebKit. Apple released additional updates alongside the major builds: iOS 26.7 and iPadOS 26.7 with more than 80 fixes, macOS Sequoia 15.8 with over 150 patches, and new builds for tvOS 27, watchOS 27 and visionOS 27. Safari 27 contains six security fixes and Xcode 27 received one patch.
Apple’s security notes do not indicate any of the patched vulnerabilities were observed being actively exploited in the wild. The company directs users and administrators to its security releases page for technical details and recommends installing the updates.
Adam Boynton, senior enterprise strategy manager at Jamf, pointed to CVE-2026-64752, a memory corruption flaw in the CoreMedia media processing framework. He said an attacker could compromise an iPhone by presenting a malicious image and that Apple removed the flawed code rather than patching it. Boynton also warned that the operational question for organizations is how quickly fixes reach corporate devices, noting that same-day support can shorten the time between a vendor release and full deployment.
Many of the vulnerabilities were discovered during 2026. System administrators and users who manage mixed device fleets should review the detailed CVE listings in Apple’s advisories to determine which patches apply to their configurations and plan testing and deployment accordingly.







