Apple Releases iOS, macOS Updates Fixing 300+ Vulnerabilities

The iOS 27 update fixes a Telephony vulnerability that could allow an attacker in a privileged network position to bypass IPSec authentication and intercept network traffic; Apple credited researchers at Ruhr University Bochum.
Appleās macOS 27 enterprise changes let organizations use Platform Single Sign-On to require Touch ID alongside a password on supervised Macs, with an Apple Watch also supported for the same authentication process.
Appleās new declarative software controls for Macs can allow or deny executable binaries based on code-signing properties, while the Endpoint Security framework can terminate processes associated with a denied binary.
Some of the vulnerabilities fixed in the new operating systems were identified with help from automated security systems, including Anthropicās Claude and OpenAIās Codex Security; macOS acknowledgments also listed OpenAI Codex Security, NVIDIA AI Red Team and Anthropic Research.
Appleās Platform Single Sign-On expansion adds web-based authentication, QR-code sign-in and other modern identity-provider workflows, broadening the enterprise authentication options beyond conventional password-based access.
Apple released iOS 27, iPadOS 27, and macOS 27 on September 14, patching over 300 vulnerabilities across its operating systems Korben. The iOS updates fix more than 120 flaws in the kernel, WebKit, networking, and authentication systems. MacOS 27 addresses over 200 vulnerabilities, including critical bugs that could enable root-level code execution and sandbox escapes Korben. Apple stated it had no evidence these vulnerabilities were being actively exploited in the wild.
Beyond security patches, Apple introduced new enterprise controls for authentication and software management. The updates require declarative management for enforcing system updates on the latest Macs. Platform Single Sign-On now supports Touch ID and Apple Watch authentication on supervised devices Korben.
iOS 27 fixes dangerous vulnerabilities in core iPhone systems. One flaw could expose saved Wi-Fi passwords on unlocked devices. Another allowed malicious shortcuts to send messages without user confirmation Korben. Attackers could also access Apple Account data or reveal which apps were installed through a malicious website.
A Telephony vulnerability posed particular risk. An attacker in a privileged network position could bypass IPSec authentication and intercept network traffic Korben. Researchers at Ruhr University Bochum identified this critical flaw. The patch closes a major gap in iOS's network security layer.
MacOS 27 addresses over 200 vulnerabilities, with the most serious enabling kernel or root-level code execution Korben. The update also fixes sandbox escapes that could bypass system isolation and Gatekeeper bypass flaws that disable security checks. Remote code execution bugs and sensitive data access issues were also patched.
Older macOS versions received critical updates too. MacOS Tahoe 26.7 and Sequoia 15.8 patches address many of the same serious flaws. Sequoia 15.8 includes an additional fix for arbitrary code execution triggered by a malicious image file Korben.
Apple added Platform Single Sign-On features allowing organizations to require Touch ID alongside passwords on managed Macs Korben. Apple Watch can also serve as a second authentication factor. The expansion includes web-based authentication and QR-code sign-in workflows for modern identity providers.
New declarative software controls for macOS let organizations allow or deny executable binaries based on code-signing properties Korben. The Endpoint Security framework can automatically terminate processes tied to denied binaries. Declarative management is now required for enforcing updates on the latest systems.
Apple credited automated security systems for finding some vulnerabilities. Anthropic's Claude and OpenAI's Codex Security tools aided the discovery process Korben. Both AI systems scanned code for weaknesses across Apple's operating systems.
MacOS security acknowledgments also listed NVIDIA's AI Red Team and Anthropic Research Korben. The collaboration between AI security tools and human researchers strengthened Apple's vulnerability identification process. This represents a growing trend of AI-assisted security work in major software releases.
Publishers
22
Articles
4
Reach
26