Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
Apple patched a record 200+ vulnerabilities in iOS 27 and macOS Golden Gate 27, including 20 kernel flaws; none exploited in the wild.
Apple's iOS 27 and iPadOS 27 releases fix roughly 126 security flaws, 20 of them in the kernel, while macOS Golden Gate 27 addresses 210 vulnerabilities, about 100 shared with the mobile release. macOS Tahoe 26.7 patches 153 unique CVEs, including 26 kernel defects that could cause memory corruption, privilege escalation, system termination, and information leaks. Notable fixes include CVE-2026-64752, a CoreMedia memory corruption flaw allowing iPhone compromise via a malicious image, and CVE-2022-3437, a heap buffer overflow in Heimdal Samba enabling denial-of-service. Apple states none of the patched flaws are known to be exploited in the wild.
- iOS 27/iPadOS 27 fix ~126 flaws, 20 kernel; macOS Golden Gate 27 patches 210
- CVE-2026-64752 CoreMedia memory corruption enables iPhone compromise via malicious image
- macOS Tahoe 26.7 patches 153 CVEs including 26 kernel defects
- Fixes span 90+ components including WebKit, Sandbox, TCC, and AppleKeyStore
- No exploitation in the wild reported by Apple
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-3437 | A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack. NVD description · AI analysis pending | 6.5 | 4% |
| — | ||
| CVE-2026-64752 | Image Processing Memory Corruption in Apple iOS, iPadOS, macOS, visionOS CVE-2026-64752 is a memory corruption vulnerability in Apple's image processing code that is triggered when a device processes a maliciously crafted image, potentially via vectors such as received messages, email attachments, or web content. Successful exploitation can lead to arbitrary code execution on the affected device, meaning an attacker could run their own code in the context of the image-processing component. The flaw affects iPhones, iPads, Macs, and Apple Vision Pro headsets running operating system versions prior to the fixed releases, and it was remediated by removing the vulnerable code entirely. The fix shipped in iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27 as part of a broader batch of roughly 200 patched vulnerabilities. There is no CVSS score yet, no known public proof of concept, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Do: Update all Apple devices to iOS 27, iPadOS 27, macOS Golden Gate 27, or visionOS 27 as soon as possible via Settings > General > Software Update, and use MDM to push the update across managed fleets. Until patched, advise users to avoid opening unsolicited images from unknown senders in Messages, Mail, and on the web. Monitor Apple's security advisories and the CISA KEV list for any change in exploitation status. | 7.3 | — |
| mass≈1 billion+ devices (all iPhone, iPad, Mac, and Vision Pro units not yet updated to the version 27 OS releases) |
Full article463 words · extracted from securityweek.com · click to collapse
Apple on Monday announced patches for a record number of vulnerabilities across its desktop and mobile operating systems, including more than 200 flaws patched with the latest major releases: iOS 27 and macOS Golden Gate 27.
iOS 27 and iPadOS 27 include fixes for about 126 security flaws, 20 of which affect the kernel.
macOS Golden Gate 27 addresses 210 vulnerabilities, roughly 100 of which are shared with the iOS 27 release.
macOS Tahoe 26.7 patches 153 unique CVEs, including 26 security defects in the kernel that could lead to memory corruption, privilege escalation, system termination, and information leaks.
While the vast majority of the issues were discovered in 2026, the macOS update also fixes CVE-2022-3437, a medium-severity heap-based buffer overflow in Samba (within Heimdal) that could lead to denial-of-service (DoS) attacks.
Approximately 100 of the resolved security defects affect both the mobile and desktop operating systems. The fixes target more than 90 platform components, including AppleKeyStore, Authentication Services, Foundation, Safe Browsing, Sandbox, Security, TCC, and WebKit.
Advertisement. Scroll to continue reading.
According to Jamf senior enterprise strategy manager Adam Boynton, one of the iOS bugs that stands out is CVE-2026-64752, a memory corruption issue in the media processing framework CoreMedia.
“An attacker could compromise an iPhone by getting a malicious image in front of the user. Interestingly, rather than patching the flawed code, Apple chose to remove it entirely,” Boynton said.
On Monday, Apple also rolled out iOS 26.7 and iPadOS 26.7 with patches for over 80 vulnerabilities (including approximately 70 resolved in iOS 27 and iPadOS 27), and macOS Sequoia 15.8 with over 150 patches (more than 140 also found in macOS Tahoe 26.7).
Additionally, the company released tvOS 27, watchOS 27, and visionOS 27 with patches for dozens of security flaws each, Safari 27 with six fixes, and Xcode 27 with one patch.
Apple makes no mention of any of these security defects being exploited in the wild. Users are advised to update their devices as soon as possible.
Additional information is available on Apple’s security releases page.
“The number of fixes in iOS 27 matters less than where they sit, and this is a kernel release rather than a browser release. For enterprises, the question is the same every September: how long does it take a fix Apple shipped on day one to reach every device that touches corporate data? That gap used to be a constraint and is now a choice, because same-day support means an estate can be current in hours rather than weeks,” Boynton said.
Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
Related: GitLab Vulnerability Exploited One Day After Disclosure
Related: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/apple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases/