Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities across iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode.
The patches arrived on September 14, 2026, through iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27, alongside iOS and iPadOS 26.7, macOS Tahoe 26.7, and macOS Sequoia 15.8.
The 273 figure represents unique CVE identifiers across Apple’s ten advisories, not the sum of every issue listed for each operating system. Many flaws affect shared frameworks and consequently appear in several releases.
Apple Fixes 273 Vulnerabilities
Apple’s individual bulletins contain 1,038 product-level CVE listings after per-page deduplication, but those references collapse to 273 unique vulnerabilities when overlaps are removed. macOS Golden Gate 27 carries the broadest coverage with 210 CVEs, followed by macOS Sequoia 15.8 with 154 and macOS Tahoe 26.7 with 153.
Among the most serious fixes is CVE-2026-65414, an out-of-bounds write in Bluetooth that could let a remote attacker crash an application or execute arbitrary code.
CVE-2026-84607, a race condition in AVEVideoEncoder, could allow a sandboxed application to run arbitrary code with kernel privileges. Apple corrected these weaknesses through stronger bounds checking and improved state management, respectively, across multiple device families.
Media processing also presents a significant attack surface. CVE-2026-64752 in CoreMedia could enable arbitrary code execution when a device processes a maliciously crafted image, while CVE-2026-65395 in ImageIO could corrupt memory through an out-of-bounds write.
FontParser, CoreText, CoreUI, SceneKit, RealityKit, Model I/O, and disk-image handlers received additional fixes for buffer overflows, integer errors, memory disclosure, crashes, and other unsafe parsing conditions. On macOS, the update closes several paths to privilege escalation and security-control bypass.
According to the security advisory Apple released, CVE-2026-84568 in autofs could allow an attacker controlling a network directory server to execute code as root, while CVE-2026-43692 in CUPS could let a remote user trigger a crash or arbitrary code execution.
Other patches strengthen Gatekeeper, sandbox enforcement, file quarantine, TCC privacy controls, SMB, WebDAV, APFS, HFS, exFAT, and disk-image processing.
Apple also fixed CVE-2026-65400 in the macOS Screen Sharing Server, an authentication flaw that could allow a network attacker to access screen sharing without valid credentials.
Privacy-related corrections prevent applications from reading persistent identifiers, identifying installed apps, accessing sensitive files, modifying protected system locations, bypassing privacy preferences, or learning a user’s location. Keychain, Sign in with Apple, CloudKit, NetworkExtension, Spotlight, Photos, Siri, and Shortcuts were among the affected components.
Web-facing exposure received substantial attention. Apple patched WebKit memory corruption, use-after-free, information disclosure, cross-site scripting, and crash bugs across its platforms.
Safari 27 alone resolves six CVEs, including CVE-2026-86898, which could enable universal cross-site scripting through a malicious webarchive, and CVE-2026-64753, which could expose sensitive information during web-content processing. Xcode 27 separately fixes CVE-2026-65393, a permissions issue that could expose user-sensitive data.
The extent of this release illustrates the importance of Apple’s unified software architecture: a vulnerability in one common framework can simultaneously impact phones, tablets, computers, watches, televisions, and spatial-computing devices. It also explains why administrators should evaluate the complete fleet rather than patching only iPhones or Macs.
Apple’s advisories for this release do not state that any of the 273 vulnerabilities were exploited in the wild, but detailed CVE information can accelerate attacker analysis and exploit development.
Users should install the latest compatible release through Software Update as soon as operationally possible. Enterprises should prioritize internet-facing Macs, systems that process untrusted media or archives, devices with Bluetooth enabled, shared workstations, developer machines, and endpoints permitted to connect to external file servers.
Security teams should verify update compliance through mobile-device management, test critical applications, and monitor for abnormal crashes, privilege escalation, unauthorized privacy changes, and suspicious network-service activity.
Prompt deployment is the clearest way to reduce exposure to this unusually large collection of Apple security flaws. The coordinated rollout therefore deserves immediate attention from consumers, developers, and enterprise security teams worldwide.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices appeared first on Cyber Security News.
