iOS 27 Fixes 126 Security Flaws, Including 20 Kernel Issues

Apple’s newest operating system updates already come packed with security protections.

Apple’s newest operating system updates already come packed with security protections. Image: ChatGPT

Apple’s iOS 27 security bulletin lists 126 CVEs, including 20 kernel issues, while iOS 26.7 offers many of the same fixes for users not ready to upgrade.

Sep 21, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

iOS 27 arrived with more than new features. Apple’s security bulletin lists 122 fixes covering 126 unique CVEs, including 20 entries tied to the iPhone kernel.

Apple released iOS 27 on Sept. 14 alongside iPadOS 27. The fixes span the kernel, Bluetooth, CoreMedia, authentication, sandboxing, WebKit, and other components that can expose sensitive device resources when vulnerabilities are exploited.

Those numbers do not mean 126 flaws were discovered after launch. They represent vulnerabilities Apple identified and patched during development before the operating system reached users.

Twenty of those entries affect the kernel, while others address vulnerabilities in Bluetooth, CoreMedia, authentication, sandboxing, WebKit, and other components that can sit between an attacker and sensitive device resources.

More than a routine update

The security work behind iOS 27 goes well beyond minor bug fixes. Apple’s bulletin covers vulnerabilities with impacts ranging from unexpected crashes and sensitive-data exposure to privilege escalation, sandbox bypasses, and arbitrary code execution.

The kernel fixes deserve particular attention because the kernel sits at the heart of iOS and controls access to memory, processes, and other system resources. One flaw tagged as CVE-2026-84622 can allow an app with root access to “read uninitialized kernel memory.” Another, tagged as CVE-2026-43689, could grant malicious apps root privileges.

Apple does not assign a single overall severity score in its iOS 27 bulletin. Instead, it describes each issue's potential impact individually.

At the same time, Apple says none of the iOS 27 flaws were known to have been exploited in the wild when it released the update.

Apple also released iOS 26.7 the same day, supporting the same iPhone 11-and-newer baseline, with around 80 of the security fixes from iOS 27. iOS 26.7 is particularly relevant for users hesitant to upgrade to Apple's new operating system, letting them keep most security fixes on an iOS version they already know.

AI helped uncover some of Apple’s security flaws

A core part of iOS 27 is an upgraded Siri AI. But iOS and iPadOS 27's relationship with artificial intelligence goes deeper than that.

In its security advisory, Apple acknowledged using AI tools to hunt for some of these vulnerabilities, alongside collaboration from security researchers. Apple credited Calif.io researchers working with Claude and Anthropic Research on multiple iOS 27 vulnerabilities. Apple's acknowledgments also name OpenAI Codex Security among the researchers credited with using AI to help uncover WebKit vulnerabilities.

Advertisement

That puts two of the biggest AI companies directly into the security story.

The pattern also goes beyond Apple. Microsoft is already using advanced AI models to discover and patch large numbers of vulnerabilities, while Google has also credited several security patches across Chrome and Android to AI.

What this means for Apple users

For iPhone users, the practical takeaway is straightforward: keep supported devices current.

Apple said none of the iOS 27 flaws were known to be actively exploited when the update was released. Even so, published vulnerability details can give attackers useful information once patches are available.

Users who want the latest features can move to iOS 27. Those not ready to upgrade can install iOS 26.7, which includes many of the same security fixes for supported iPhones.

That matters because security risk is not limited to headline kernel flaws. Vulnerabilities in WebKit, Bluetooth, media processing, and authentication can all create different paths into a device, making regular updates important even when there is no confirmed active exploitation.

Mac users got some of the security gift, too. Apple released macOS Golden Gate 27 alongside iOS 27, with 204 security fixes, according to MacWorld.

In other words, this was a broad Apple security refresh, not an iPhone-only patch cycle, and the best you can do is update. To do that on your compatible iPhone, iPad, or Mac:

Open Settings > General > Software Update > Check for Updates > Upgrade Tonight/Upgrade Now.

For iPhones, both iOS 26.7 and iOS 27 are available for iPhone 11 and later. iPad users can check Apple’s compatibility lists for iPadOS 27 and iPadOS 26.7 to see which update their device supports.

Mac users can similarly check Apple’s compatibility requirements for macOS 27 and macOS 26.7.

Other news: OpenAI disclosed six AI misalignment incidents in which models hid mistakes, fabricated data, used exposed credentials, and found unauthorized ways to communicate, prompting new calls for stronger external controls around AI agents.

Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.