Apple patches 257 flaws across iOS 27 and macOS 27

Published

Apple shipped its annual operating system release on September 14, and the security notes that came with it are long. A consolidated bulletin published a day later by Hong Kong's computer emergency response team, HKCERT, lists 257 distinct CVE identifiers across ten Apple products, from the iPhone to the Xcode toolchain developers build with.

The spread matters more than the number. This is not one product line getting a fix. It is every Apple device class at once.

Every device class in one day

HKCERT's bulletin names the affected software as versions earlier than iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, Safari 27, tvOS 27, visionOS 27, watchOS 27 and Xcode 27. Apple's own security content pages date iOS 27 and iPadOS 27 and macOS Golden Gate 27 to September 14, one day before the bulletin.

The impacts HKCERT lists for the set are remote code execution, elevation of privilege, information disclosure, denial of service, data manipulation, security restriction bypass, spoofing and cross site scripting. It rates the release Medium Risk overall. The oldest identifier in the list is CVE-2022-3437, a 2022 record, and the bulletin does not say which component that one belongs to.

The bulletin stops where Apple's notes begin

What the consolidated bulletin does not carry is worth stating plainly, because it sets the limit on what anyone can responsibly say today. It publishes no CVSS scores, no component by component breakdown, and no note that any of these flaws is being exploited in the wild. It does not describe how any individual bug works. That detail, including which framework each CVE lands in and who reported it, sits in Apple's own security content pages, which the bulletin links product by product.

The gap is routine for a consolidated national CERT advisory. It is not evidence that the flaws are minor, and it is not evidence that they are severe. It simply means the vendor's notes are the document to read if you need to prioritize within the release rather than take all of it.

Update to 27, or take the 26.7 track

The bulletin lists fixes on two tracks, so an estate that is not ready to move to a new major version still has somewhere to go. On mobile that is iOS 27 and iPadOS 27, or iOS 26.7 and iPadOS 26.7. On the desktop it is macOS Golden Gate 27, macOS Tahoe 26.7 or macOS Sequoia 15.8. Safari 27, tvOS 27, visionOS 27, watchOS 27 and Xcode 27 complete the set. No workaround is offered for any of it, which is normal for a scheduled platform release: the update is the fix.

Apple patching is not an abstract hygiene exercise. In August the company fixed an image parsing bug that could run code on an iPhone, and this month researchers documented a fake Malaysian parking site that attacked iPhones with no tap at all. Release day is the one day a year the whole fleet can be brought current in a single pass, and it is the cheapest day to spend on it.

The full advisory, including the complete identifier list and the links to each of Apple's ten product pages, is in HKCERT's bulletin.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions