Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns of 17 Active Directory Attack Techniques
September 15, 2026
New Tactics: Malware Uses Rotating Infrastructure to Evade Detection
September 15, 2026
Apple Patches 273 Flaws Across iOS, macOS, watchOS, and tvOS
September 15, 2026
Home/CyberSecurity News/Apple Patches 273 Flaws Across iOS, macOS, watchOS, and tvOS
CyberSecurity News

Apple Patches 273 Flaws Across iOS, macOS, watchOS, and tvOS

Key Takeaways Apple has issued a massive security update, patching 273 unique vulnerabilities across its entire product ecosystem. Affected devices include iPhones, iPads, Macs, Apple Watches, Apple...

Jennifer sherman
Jennifer sherman
September 15, 2026 4 Min Read
2 0

Key Takeaways

  • Apple has issued a massive security update, patching 273 unique vulnerabilities across its entire product ecosystem.
  • Affected devices include iPhones, iPads, Macs, Apple Watches, Apple TVs, Vision Pro, Safari, and Xcode.
  • The flaws range from remote code execution and privilege escalation to information disclosure and authentication bypasses.
  • Users are strongly advised to update their devices immediately to the latest compatible software versions.

Apple Addresses 273 Critical Flaws Across Ecosystem

Apple has rolled out an extensive series of security updates, addressing a staggering 273 distinct vulnerabilities spanning its wide array of devices and software, including iPhones, iPads, Macs, Apple Watches, Apple TVs, Vision Pro, Safari, and Xcode. This coordinated release represents one of the company’s most significant security overhauls to date.

Table Of Content

  • Key Takeaways
  • Apple Addresses 273 Critical Flaws Across Ecosystem
  • Widespread Vulnerability Coverage
  • Web-Facing Exposure and Developer Tools
  • What You Should Do

The patches were deployed on September 14, 2026, through a comprehensive suite of updates: iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27. Supplemental updates were also released for iOS and iPadOS 26.7, macOS Tahoe 26.7, and macOS Sequoia 15.8.

While Apple’s ten individual security advisories listed 1,038 product-level CVEs, the figure of 273 represents the number of unique Common Vulnerabilities and Exposures (CVE) identifiers after accounting for overlaps. Many of these flaws impact shared system frameworks, leading to their appearance across multiple operating system releases.

Widespread Vulnerability Coverage

An analysis of the updates reveals that macOS Golden Gate 27 incorporates fixes for the largest number of vulnerabilities, with 210 CVEs. This is followed by macOS Sequoia 15.8, which addresses 154 CVEs, and macOS Tahoe 26.7, with 153 CVEs.

Among the most critical issues resolved is CVE-2026-65414, an out-of-bounds write vulnerability in Bluetooth. This flaw could potentially allow a remote attacker to trigger an application crash or execute arbitrary code on affected devices. Another significant fix, CVE-2026-84607, addresses a race condition within AVEVideoEncoder, which could enable a sandboxed application to execute arbitrary code with elevated kernel privileges. Apple mitigated these weaknesses through enhanced bounds checking and improved state management across its diverse product lines.

Media processing components also presented a substantial attack surface. CVE-2026-64752 in CoreMedia could lead to arbitrary code execution if a device processes a maliciously crafted image. Similarly, CVE-2026-65395 in ImageIO was patched to prevent memory corruption caused by an out-of-bounds write. Further updates targeted FontParser, CoreText, CoreUI, SceneKit, RealityKit, Model I/O, and disk-image handlers, correcting issues like buffer overflows, integer errors, memory disclosure, application crashes, and other unsafe parsing conditions. On macOS, several pathways to privilege escalation and security-control bypass were also closed.

According to the security advisory Apple released, CVE-2026-84568 in autofs could permit an attacker controlling a network directory server to execute code with root privileges. Additionally, CVE-2026-43692 in CUPS was patched to prevent remote users from triggering crashes or arbitrary code execution.

Other significant patches enhance the security of core macOS features, including Gatekeeper, sandbox enforcement, file quarantine, TCC privacy controls, SMB, WebDAV, APFS, HFS, exFAT, and general disk-image processing.

A notable authentication flaw, CVE-2026-65400, was also fixed in the macOS Screen Sharing Server. This vulnerability could have allowed a network attacker to gain unauthorized access to screen sharing functionality without valid credentials.

Privacy-related corrections were a significant focus of this release, preventing applications from reading persistent identifiers, identifying installed applications, accessing sensitive files, modifying protected system locations, bypassing privacy preferences, or tracking a user’s location. Components such as Keychain, Sign in with Apple, CloudKit, NetworkExtension, Spotlight, Photos, Siri, and Shortcuts were among those affected and subsequently secured.

Web-Facing Exposure and Developer Tools

Web-facing vulnerabilities received substantial attention, with Apple patching WebKit to address memory corruption, use-after-free conditions, information disclosure, cross-site scripting (XSS), and crash bugs across its various platforms.

Safari 27 alone resolves six CVEs, including CVE-2026-86898, which could facilitate universal cross-site scripting through a malicious webarchive, and CVE-2026-64753, a flaw that could expose sensitive information during web-content processing. Xcode 27 also received a separate fix for CVE-2026-65393, a permissions issue that could expose sensitive user data.

The extensive nature of this security release underscores the interconnectedness of Apple’s unified software architecture. A single vulnerability in a common framework can concurrently impact a broad range of devices, from smartphones and tablets to computers, wearables, televisions, and even spatial-computing devices. This highlights the critical need for administrators to assess their entire fleet of Apple devices rather than selectively patching only certain product categories.

Apple’s advisories for this release do not indicate that any of the 273 vulnerabilities have been exploited in the wild. However, the public disclosure of detailed CVE information can accelerate analysis and exploit development by malicious actors.

What You Should Do

  • Update Immediately: All users should install the latest compatible software updates via Software Update on their devices as soon as possible.
  • Prioritize Critical Systems: Enterprises should prioritize updates for internet-facing Macs, systems that process untrusted media or archives, devices with Bluetooth enabled, shared workstations, developer machines, and endpoints that connect to external file servers.
  • Verify Compliance: Security teams should utilize mobile-device management (MDM) solutions to verify update compliance across their fleet.
  • Monitor for Anomalies: Be vigilant for abnormal application crashes, signs of privilege escalation, unauthorized changes to privacy settings, and suspicious network-service activity post-update.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Microsoft Forbids AI Models From Launching Cyberattacks, Escalating Access

Next Post

New Tactics: Malware Uses Rotating Infrastructure to Evade Detection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Offer Uncensored Luciferus AI Service on Dark Web Forums
September 15, 2026
Cisco Secure Email Gateway Critical Zero-Day Actively Exploited, CISA Warns
September 15, 2026
Critical cPanel LiteSpeed Web Server Flaw Lets Users Gain Root Access
September 15, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us