iOS 27 and iPadOS 27 address roughly 126 flaws, while macOS Golden Gate 27 lists about 210. Apple’s September operating-system releases close an unusually large set of security flaws. Independent counts put iOS and iPadOS 27 at roughly 126 fixes and macOS Golden Gate 27 at about 210, with substantial overlap between platforms.

Apple: verified facts

Verified event facts
Released September 14, 2026 Apple
iOS/iPadOS 27 About 126 fixes SecurityWeek; MacRumors
macOS Golden Gate 27 About 210 fixes SecurityWeek
Known exploitation None marked as actively exploited at publication MacRumors; MacObserver

Apple security updates implementation flowFour stages show scope, controls, pilot and measured rollout.Apple security updates: evidence flowScopeControlsPilotMeasure

What the update changes

Apple’s September operating-system releases close an unusually large set of security flaws. Independent counts put iOS and iPadOS 27 at roughly 126 fixes and macOS Golden Gate 27 at about 210, with substantial overlap between platforms.

The totals should not be added as though every entry were unique. Many components and CVEs are shared across iPhone, iPad and Mac. The practical message is that the release touches a broad attack surface, including kernel, Bluetooth, CoreMedia, WebKit and system services.

Kernel defects include paths to memory corruption, privilege escalation, termination and information disclosure. Other entries cover malicious media and remote interactions. Apple’s pages did not label the listed flaws as actively exploited at publication, so this is a prioritised patch cycle rather than evidence of a confirmed campaign.

Organisations should inventory supported hardware and choose between the new major version and available 26.7 security updates where appropriate. Apple documented more than 80 fixes in iOS 26.7, with many shared with iOS 27, but the pages are not identical and should be compared by device policy.

A major-version update can affect applications, device management and authentication. Fleet administrators should test critical apps, VPNs, certificates, peripherals and recovery workflows on representative devices, then phase deployment quickly. High-risk users and internet-facing systems should not wait for a perfect broad rollout.

The volume also reflects increased automated vulnerability discovery. Apple credits tools including Anthropic’s Claude and OpenAI Codex Security for some findings. Automated discovery helps defenders, but publication also gives attackers a map, which shortens the safe window for unpatched devices.

Users should verify backups, install through the system updater and avoid unsolicited links claiming to provide a patch. Enterprises need compliance reporting that shows actual installed versions rather than whether an update command was sent.

Apple security updates are notable for scale, but patch counts do not rank every flaw equally. Teams should combine the vendor advisories with asset exposure, exploitability and business impact, then confirm successful installation across the fleet.

Related Lapaas Voice coverage

Read our coverage of Cohere encrypted inference and NVIDIA CUDA-Q logical quantum codesign for adjacent context.

Frequently asked questions

What is Apple?

iOS 27 and iPadOS 27 address roughly 126 flaws, while macOS Golden Gate 27 lists about 210.

What changed?

The sets overlap, so the figures should not be added as a count of unique vulnerabilities.

What should users verify?

Apple did not mark the listed flaws as actively exploited at publication, but fleet administrators should test and deploy promptly.

Sources

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.