Product1 publisher3 min readPublished
Apple bundles more than 120 security fixes into the iOS 27 upgrade
Apple published the security content for iOS 27 and iPadOS 27 on release day, and for anyone running a managed fleet the impacts listed there decide how long the upgrade can wait. The hardware list decides who is eligible at all.
The Product Desk · Product desk

What happened
- Apple detailed the security content of iOS 27 and iPadOS 27 on the day both shipped, and its page lists more than 120 fixes.
- The impacts described include arbitrary code execution, kernel or root privilege escalation, access to sensitive user data and bypassing system protections.
- The same day carried standalone Safari and Xcode updates, with Apple pushing security fixes across dozens of devices.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision With macOS 26.7 and macOS 15.8 published beside macOS 27 and no iOS point release out, an iPhone administrator who wants these fixes is deciding whether to take a major version now.
- exposure The privacy items reach devices through apps a user already installed, so a deferral leaves an exposure that no phishing training or user comms will cover.
- constraint Hardware below the Available for line, an iPad 8th generation or an iPhone X, cannot take this release, so remediation there is a purchase.
- cost The team pays for the 120-plus fixes in regression testing of internal apps, done inside the same window in which the unpatched exposure is running.
Open the security content page and search for the word kernel. A hit comes up under APFS, CVE-2026-84523: an app could cause unexpected system termination or write kernel memory. Apple says it addressed an out-of-bounds write with improved bounds checking, and credits Cem Onat Karagun and an anonymous researcher [7].
Keep counting from the top. Seven CVEs appear across the first seven component entries, from Accelerate Framework through Apple Account, out of a list Apple describes as more than 120 [14]. Seven of 120 is under 6 percent of the release, and the entries are ordered alphabetically by component, so the list has not left the A's yet [13].
Five of those seven are one app reaching something that belongs to somewhere else: sensitive user data (CVE-2026-43664) [9], the set of other apps a user has installed (CVE-2026-64761) [8], a Privacy preferences bypass (CVE-2026-65404) [10], a persistent account identifier readable by a local app (CVE-2026-86888) [11], and the Sign In With Apple flow, where Apple says an app could use it to access the user's Apple Account (CVE-2026-20683) [12]. The other two are out-of-bounds writes, one of them triggered by processing a maliciously crafted image [6][15].
On the Mac side Apple gave administrators two routes on the same day: macOS 27, and point updates macOS 26.7 and macOS 15.8 [3]. The 9to5mac account of the day's releases covers those two point updates. Apple has not published an iOS point release [17]. Until Apple publishes one, the only iPhone build with these fixes attached to it is 27.
Executives and administrators are judging different things. Upgrades get argued as feature adoption, and the security content page turns them into a question about a date and an owner. You cannot train users out of an app that can enumerate your other installed apps, because the attacker in that description is software the user already agreed to install [8].
Two questions per device group settle most of it. Is the hardware on the Available for line? For these entries that line starts at iPhone 11, iPad 9th generation, iPad Air 4th generation, iPad mini 6th generation, iPad Pro 11-inch 2nd generation and iPad Pro 12.9-inch 4th generation [5]. And does the app that device exists to run work on 27.
Two yeses, and the upgrade ships this week. Eligible hardware with a broken line-of-business app is the only case that needs a real decision. The decision is how many days of exposure to the arbitrary code execution and kernel or root privilege escalation on that page you buy with the delay [2]. The iPad 8th generation in the warehouse is not on the Available for line, and for that hardware this release does not list a fix.
What to watch
- Whether Apple publishes an iOS or iPadOS point release carrying the same CVEs. A point release would give fleets these fixes without a major version upgrade.
- Whether any of the named CVEs, in particular APFS CVE-2026-84523, turns up in exploited-in-the-wild reporting or a government exploited-vulnerabilities catalogue.
- Whether later Apple advisories extend an Available for line below iPhone 11 and iPad 9th generation.