[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9D61uM367F1F3vAyTnIZsauZMB5Y8dwSXmU3sN_9-Wk":3},{"article":4,"iocs":39},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"9fc44b7b-5ae4-4340-98c3-4a9d28d3a096","Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases","apple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases-809b0a","The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases appeared first on SecurityWeek.","Apple has released major updates for its operating systems, including iOS 27 and macOS Golden Gate 27, addressing a significant number of vulnerabilities. iOS 27 and iPadOS 27 fix approximately 126 flaws, while macOS Golden Gate 27 resolves 210, with about 100 shared between them. These patches address critical issues like memory corruption and privilege escalation, with one notable vulnerability in CoreMedia being addressed by removing the affected code entirely.","Apple releases iOS 27 and macOS Golden Gate 27, patching over 200 vulnerabilities.","Apple on Monday announced patches for a record number of vulnerabilities across its desktop and mobile operating systems, including more than 200 flaws patched with the latest major releases: iOS 27 and macOS Golden Gate 27. iOS 27 and iPadOS 27 include fixes for about 126 security flaws, 20 of which affect the kernel. macOS Golden Gate 27 addresses 210 vulnerabilities, roughly 100 of which are shared with the iOS 27 release. macOS Tahoe 26.7 patches 153 unique CVEs, including 26 security defects in the kernel that could lead to memory corruption, privilege escalation, system termination, and information leaks. While the vast majority of the issues were discovered in 2026, the macOS update also fixes CVE-2022-3437, a medium-severity heap-based buffer overflow in Samba (within Heimdal) that could lead to denial-of-service (DoS) attacks. Approximately 100 of the resolved security defects affect both the mobile and desktop operating systems. The fixes target more than 90 platform components, including AppleKeyStore, Authentication Services, Foundation, Safe Browsing, Sandbox, Security, TCC, and WebKit.Advertisement. Scroll to continue reading. According to Jamf senior enterprise strategy manager Adam Boynton, one of the iOS bugs that stands out is CVE-2026-64752, a memory corruption issue in the media processing framework CoreMedia. “An attacker could compromise an iPhone by getting a malicious image in front of the user. Interestingly, rather than patching the flawed code, Apple chose to remove it entirely,” Boynton said. On Monday, Apple also rolled out iOS 26.7 and iPadOS 26.7 with patches for over 80 vulnerabilities (including approximately 70 resolved in iOS 27 and iPadOS 27), and macOS Sequoia 15.8 with over 150 patches (more than 140 also found in macOS Tahoe 26.7). Additionally, the company released tvOS 27, watchOS 27, and visionOS 27 with patches for dozens of security flaws each, Safari 27 with six fixes, and Xcode 27 with one patch. Apple makes no mention of any of these security defects being exploited in the wild. Users are advised to update their devices as soon as possible. Additional information is available on Apple’s security releases page. “The number of fixes in iOS 27 matters less than where they sit, and this is a kernel release rather than a browser release. For enterprises, the question is the same every September: how long does it take a fix Apple shipped on day one to reach every device that touches corporate data? That gap used to be a constraint and is now a choice, because same-day support means an estate can be current in hours rather than weeks,” Boynton said. Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution Related: GitLab Vulnerability Exploited One Day After Disclosure Related: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code ExecutionThree JFrog Artifactory Flaws Exploited for Backdoor DeploymentConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-DaysGitLab Vulnerability Exploited One Day After DisclosureCheck Point Patches Critical VPN VulnerabilitiesSurfshark Systems Targeted by HackersPaperCut Flaws Exploited in AI-Powered Attacks Latest News 240,000 Hit by Data Breach at Japan’s Digital AgencyMicrosoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety ConstraintsHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix AttackRoot RCE Zero-Day in Cisco Secure Email Gateway Under Active ExploitationBeijing Hits Back at Anthropic CEO’s Call to Curb China’s AI DevelopmentNew Warnings About the Risks of AI to Humanity Revive a Long-Running DebatePersonal, Financial Info Exposed in Revolut Data BreachThe Race to Control AI and Protect What Makes Us Human Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fapple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F09\u002FApple-MacBook-iPhone.jpeg","2026-09-15T11:06:11+00:00","2026-09-15T12:00:19.13534+00:00",8,[18,21,23,25,27,29],{"name":19,"type":20},"iOS 27","product",{"name":22,"type":20},"macOS Golden Gate 27",{"name":24,"type":20},"iPadOS 27",{"name":26,"type":20},"macOS Tahoe 26.7",{"name":28,"type":20},"Samba",{"name":30,"type":20},"Heimdal","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":31,"icon":33,"name":34,"slug":35},null,"Vulnerabilities","vulnerabilities",[37],{"category":38},{"id":31,"icon":33,"name":34,"slug":35},[40,44],{"type":41,"value":42,"context":43},"cve","CVE-2022-3437","Medium-severity heap-based buffer overflow in Samba (within Heimdal) in macOS Tahoe 26.7.",{"type":41,"value":45,"context":46},"CVE-2026-64752","Memory corruption issue in CoreMedia framework in iOS."]