Apple issued annual security updates across its operating systems, patching 261 vulnerabilities—its largest annual remediation total reported to date. The fixes span the Kernel, WebKit, SMB, CUPS, ImageIO, SceneKit, Disk Images, and privacy and sandboxing services. Documented impacts include arbitrary code execution, root or kernel privilege escalation, memory disclosure and corruption, sandbox escapes, Gatekeeper and privacy-control bypasses, data exposure, and denial of service through malicious web content and files, network shares and servers, accessories, or local applications.
iOS 27 fixes more than 100 vulnerabilities, while the security-only iOS 26.7 update fixes more than 80, including 75 issues shared with iOS 27; this gives organizations deferring the iOS 27 upgrade a path to remediate many of the same risks. Notable issues include a kernel flaw through which a malicious application could obtain root privileges and a Bluetooth flaw that could permit remote code execution. Apple also released macOS Tahoe 26.7 and macOS Sequoia 15.8 for systems remaining on older macOS versions. No vulnerabilities are known to be actively exploited, but published technical details heighten exposure for unpatched devices; Apple credited Anthropic Claude for three fixes and recognized OpenAI Codex Security.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Apple published security details for iOS 27 and iOS 26.7, including kernel flaws that could enable root access and a Bluetooth flaw that could enable remote code execution. Apple said none of the addressed issues were known to be actively exploited and credited three fixes to Anthropic Claude, with additional recognition for OpenAI Codex Security.
Apple released macOS Tahoe 26.7 and macOS Sequoia 15.8 with security fixes for older Macs and users not upgrading to macOS Golden Gate.
Apple released iOS 27 with fixes for more than 100 vulnerabilities and iOS 26.7, a security-only update, with more than 80 fixes. The releases share 75 fixes, providing an update path for users remaining on iOS 26.
Apple released annual updates across its operating systems, introducing new features and patching 261 vulnerabilities, described as the company's largest vulnerability total in a single annual update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
tidbits.com
Open sourcemalware.news
Open sourcemacrumors.com
Open sourceisc.sans.edu
Open sourcemacrumors.com
Open sourcemacrumors.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.