Apple’s largest security release of the year arrived on September 14, closing hundreds of holes in phones, Macs, watches and headsets on the same day.
The macOS 27 Golden Gate advisory lists more than 200 separate entries, while the iOS 27 and iPadOS 27 notice carries more than 120. Nothing in either list was flagged as under attack before the fixes shipped, and outside reviewers reached the same conclusion after reading the release notes.
Older branches get their own repairs
Devices that stay on the previous generation are covered too. iOS 26.7 and iPadOS 26.7 close roughly 82 flaws, and the Mac side gets macOS Tahoe 26.7 alongside macOS Sequoia 15.8. Tahoe has now entered its security-only window, and Sequoia is beginning its final year of patches. Sonoma, whose support ended, received nothing.
Safari 27 ships a separate six-bug list dominated by WebKit and Safe Browsing repairs. watchOS 27, tvOS 27 and visionOS 27 each carry their own advisories, and Xcode 27 adds a single entry.
A permissions bug held back for the new release
The sharpest single item is a permissions flaw that let an app sidestep Apple Intelligence’s security prompts. It appears only in the macOS 27 list, hinting that the repair depends on the newest system rather than being backported to Tahoe or Sequoia. Apple documents it as CVE-2026-84601.
Golden Gate also carries an updated XProtect Remediator build, version 159, which has not yet been offered through Software Update on its own.
Anyone holding hardware that cannot move to the new release can stay put for now, because the 26.7 branch is still receiving full coverage. Updates install through Software Update on each device.