Apple has released a major round of security updates covering its iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode platforms.
The September 14, 2026 rollout addresses 273 unique CVE vulnerabilities across Apple’s latest software releases. The updates include iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27, along with security updates for earlier supported versions.
The 273 figure represents unique vulnerabilities. Because many Apple products share the same frameworks and components, the same CVE can appear in multiple product advisories.
Major Security Issues Fixed
Several of the vulnerabilities could have serious security consequences, particularly those involving memory corruption, privilege escalation, and malicious file or media processing.
Some notable fixes include:
- Bluetooth: CVE-2026-65414 could allow a remote attacker to crash an application or potentially execute code.
- AVEVideoEncoder: CVE-2026-84607 could allow a sandboxed application to execute code with kernel-level privileges.
- CoreMedia: CVE-2026-64752 addresses a flaw that could lead to code execution when processing specially crafted images.
- ImageIO: CVE-2026-65395 fixes a memory corruption vulnerability.
- autofs: CVE-2026-84568 could allow code execution with root privileges when an attacker controls a network directory server.
- CUPS: CVE-2026-43692 could result in application crashes or arbitrary code execution.
- Screen Sharing: CVE-2026-65400 fixes an authentication issue that could allow network attackers to access screen sharing without valid credentials.
Apple also addressed weaknesses across FontParser, CoreText, CoreUI, SceneKit, RealityKit, Model I/O, disk-image processing, APFS, SMB, WebDAV, and other components.
Privacy protections were strengthened as well. Several fixes prevent applications from accessing information they should not be able to obtain, including persistent identifiers, sensitive files, location information, and protected system resources.
WebKit and Other Attack Surfaces Also Patched
Apple’s web technologies received multiple security fixes in this release. WebKit vulnerabilities included memory corruption, use-after-free, information disclosure, cross-site scripting, and crash-related issues.
Safari 27 fixes six CVEs, including issues that could allow malicious web content to access sensitive information or bypass normal browser security protections.
Xcode 27 also received a security fix for a permissions issue that could expose sensitive user data.
The large number of fixes demonstrates how a vulnerability in a shared Apple component can affect several product families at the same time.
For users and organizations, this means security updates should be viewed across the entire Apple device fleet, rather than focusing only on iPhones or Macs.
What Users and Security Teams Should Do
Apple has not stated in these advisories that the 273 vulnerabilities are being actively exploited in the wild. However, publicly available vulnerability details can help attackers study affected components and develop exploits.
Organizations should:
- Install the latest supported Apple security updates.
- Use MDM to verify update compliance across managed devices.
- Prioritize internet-facing Macs and shared workstations.
- Pay attention to systems processing untrusted files, images, or archives.
- Update developer machines running Xcode.
- Review devices with Bluetooth and external network services enabled.
- Monitor for unusual crashes, privilege escalation, and unexpected system changes.
- Test important business applications after updating.
Consumers should also check Software Update and install the latest compatible release.
With hundreds of vulnerabilities addressed across multiple Apple platforms, keeping devices patched is an important step in reducing exposure to security attacks.