iOS 27 and iPadOS 27 address roughly 126 flaws, while macOS Golden Gate 27 lists about 210. Apple’s September operating-system releases close an unusually large set of security flaws. Independent counts put iOS and iPadOS 27 at roughly 126 fixes and macOS Golden Gate 27 at about 210, with substantial overlap between platforms.
Apple: verified facts
| Released | September 14, 2026 | Apple |
|---|---|---|
| iOS/iPadOS 27 | About 126 fixes | SecurityWeek; MacRumors |
| macOS Golden Gate 27 | About 210 fixes | SecurityWeek |
| Known exploitation | None marked as actively exploited at publication | MacRumors; MacObserver |
What the update changes
Apple’s September operating-system releases close an unusually large set of security flaws. Independent counts put iOS and iPadOS 27 at roughly 126 fixes and macOS Golden Gate 27 at about 210, with substantial overlap between platforms.
The totals should not be added as though every entry were unique. Many components and CVEs are shared across iPhone, iPad and Mac. The practical message is that the release touches a broad attack surface, including kernel, Bluetooth, CoreMedia, WebKit and system services.
Kernel defects include paths to memory corruption, privilege escalation, termination and information disclosure. Other entries cover malicious media and remote interactions. Apple’s pages did not label the listed flaws as actively exploited at publication, so this is a prioritised patch cycle rather than evidence of a confirmed campaign.
Organisations should inventory supported hardware and choose between the new major version and available 26.7 security updates where appropriate. Apple documented more than 80 fixes in iOS 26.7, with many shared with iOS 27, but the pages are not identical and should be compared by device policy.
A major-version update can affect applications, device management and authentication. Fleet administrators should test critical apps, VPNs, certificates, peripherals and recovery workflows on representative devices, then phase deployment quickly. High-risk users and internet-facing systems should not wait for a perfect broad rollout.
The volume also reflects increased automated vulnerability discovery. Apple credits tools including Anthropic’s Claude and OpenAI Codex Security for some findings. Automated discovery helps defenders, but publication also gives attackers a map, which shortens the safe window for unpatched devices.
Users should verify backups, install through the system updater and avoid unsolicited links claiming to provide a patch. Enterprises need compliance reporting that shows actual installed versions rather than whether an update command was sent.
Apple security updates are notable for scale, but patch counts do not rank every flaw equally. Teams should combine the vendor advisories with asset exposure, exploitability and business impact, then confirm successful installation across the fleet.
Related Lapaas Voice coverage
Read our coverage of Cohere encrypted inference and NVIDIA CUDA-Q logical quantum codesign for adjacent context.
Frequently asked questions
What is Apple?
iOS 27 and iPadOS 27 address roughly 126 flaws, while macOS Golden Gate 27 lists about 210.
What changed?
The sets overlap, so the figures should not be added as a count of unique vulnerabilities.
What should users verify?
Apple did not mark the listed flaws as actively exploited at publication, but fleet administrators should test and deploy promptly.
Sources
- Apple Security Releases — 2026-09-14
- SecurityWeek — 2026-09-15
- MacRumors — 2026-09-14
- Macworld — 2026-09-14
- MacObserver — 2026-09-15
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



