iOS 27 and macOS Golden Gate 27 Patch 336 Security Vulnerabilities

Apple pushed out iOS 27, iPadOS 27, and macOS Golden Gate 27 yesterday, and the security notes attached to them are dense. Between the two documents, Apple closed 336 individual vulnerabilities across iPhone, iPad, and Mac.

Apple published the full breakdown in two separate support documents, one covering iOS 27 and iPadOS 27 and a second one dedicated to macOS Golden Gate 27. Neither document flags any of the fixes as actively exploited in the wild.

iOS 27, iPadOS 27, macOS 27, tvOS 27, and watchOS 27 Public Beta 4

iOS 27 and iPadOS 27 Close 126 Security Holes

The iOS 27 and iPadOS 27 advisory lists 126 CVEs. Coverage runs from iPhone 11 and later through a wide range of iPad models, starting with iPad Pro 12.9-inch 4th generation and iPad Pro 11-inch 2nd generation.

Kernel bugs make up the single biggest group, with 20 separate fixes covering use-after-free issues, race conditions, and out-of-bounds writes that could let an app read or corrupt kernel memory. WebKit picked up three patches, including one that closed a path for a malicious webarchive file to run cross-site scripting on any site. Baseband and Bluetooth each got two fixes addressing remote attacks that could crash a device or, in Bluetooth’s case, run arbitrary code over the air.

Component Fixes in iOS 27 / iPadOS 27
Kernel 20
CoreUI 5
SceneKit 5
WebKit 3
CoreMedia 3
AVEVideoEncoder 3

macOS Golden Gate 27 Fixes More Than 200 Flaws

The Mac side carries the heavier load. macOS Golden Gate 27 patches 210 CVEs, and the Kernel alone accounts for 33 of them, more than in any single category on iOS 27 or iPadOS 27.

CUPS, the printing stack, took 10 separate fixes, several of them tied to root privilege escalation through crafted print jobs. SMB got 9 patches covering kernel memory corruption when connecting to a malicious server or share. WebDAV, Disk Images, and CoreUI each picked up 4 or 5 fixes apiece.

Component Fixes in macOS Golden Gate 27
Kernel 33
CUPS 10
SMB 9
SceneKit 8
Disk Images 5
CoreUI 5
WebDAV 4

Anthropic’s Claude Gets Credit Alongside Human Researchers

A handful of the patched bugs list “Calif.io in collaboration with Claude and Anthropic Research” as the reporting credit, sitting right next to individually named human researchers like Bruce Dang. The credit shows up on both documents.

In iOS 27 and iPadOS 27, it covers an AVEVideoEncoder crash bug and a Foundation denial-of-service issue. macOS Golden Gate 27 carries the same credit on a wider cluster, including fixes in Foundation, SMB, and WebDAV. Apple’s acknowledgment section doesn’t explain how the AI model was used in the research, only that Calif.io ran it in collaboration with Anthropic.

  • CVE-2026-65410 (AVEVideoEncoder, both platforms)
  • CVE-2026-65409 (Foundation, both platforms)
  • CVE-2026-43690, CVE-2026-43719, CVE-2026-65376 (SMB, macOS Golden Gate 27)
  • CVE-2026-65374, CVE-2026-65375, CVE-2026-43677 (WebDAV, macOS Golden Gate 27)
Newsletter
Never miss an Apple story
One email a day, the news that matters. No spam, unsubscribe anytime.
About the Author

Imran Hussain is the founder and editor of iThinkDifferent, which he launched in 2008 to cover Apple news, reviews, and how-to guides. He has spent over 15 years writing about iOS, macOS, and the wider Apple ecosystem, with a focus on hands-on guides - installing developer betas, troubleshooting, and walking through new features on his own devices. Based in Dubai, he also loves to cover photography, gaming, and the tech industry more broadly on his social media profiles.

Leave a Reply