Apple has launched a significant security update to rectify 273 critical vulnerabilities affecting a wide range of its devices, including iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode. This update, which is among the largest coordinated security efforts by Apple, was issued on September 14, 2026.
Details of the Security Patches
The updates were delivered via iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27. Additionally, updates for iOS and iPadOS 26.7, macOS Tahoe 26.7, and macOS Sequoia 15.8 were also released. These updates address unique CVE identifiers across ten advisories, focusing on shared frameworks that impact multiple releases.
After removing duplicates, the bulletins document 1,038 product-level CVE listings that consolidate into 273 unique vulnerabilities. macOS Golden Gate 27 included the most comprehensive coverage with 210 CVEs, followed by macOS Sequoia 15.8 with 154, and macOS Tahoe 26.7 with 153.
Critical Vulnerabilities Addressed
Among the significant patches, CVE-2026-65414 resolves an out-of-bounds write in Bluetooth that could allow remote code execution. Another critical fix, CVE-2026-84607, addresses a race condition in AVEVideoEncoder, potentially enabling arbitrary code execution with kernel privileges.
Media processing vulnerabilities such as CVE-2026-64752 and CVE-2026-65395, which risk arbitrary code execution and memory corruption, respectively, were also fixed. Apple fortified its systems by improving bounds checking and state management techniques.
Impact and Recommendations
The update also improves protections against attacks targeting Gatekeeper, sandbox enforcement, file quarantine, and privacy controls among others. In Safari 27, Apple resolved critical vulnerabilities, including cross-site scripting and information disclosure threats.
Although Apple has not reported real-world exploitation of these vulnerabilities, the detailed disclosure of CVE information could potentially aid attackers. Consequently, it is imperative for users to update their devices promptly.
Enterprises should prioritize updates on systems exposed to the internet, those managing untrusted media, and devices with Bluetooth functionalities. Comprehensive fleet evaluation is recommended to ensure complete coverage.
Security teams need to confirm update compliance, test critical applications, and monitor for anomalies. Timely deployment of these updates is crucial for minimizing exposure to the addressed security threats.
