Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products — the largest single patch cycle in the company’s history.
Scale of the update: 260+ CVEs, iOS 27 and macOS 27 Golden Gate
Apple’s latest updates represent a company record. The vendor’s newest mobile release, iOS 27, fixes 122 security vulnerabilities, while macOS 27 Golden Gate patches 204, according to the company. Taken together, Apple addressed more than 260 CVEs across its platforms in this single cycle. The Register contrasted that number with Microsoft’s earlier disclosure of 974 bugs, noting the relative scale, but emphasized that within Apple’s product line this is an unprecedented patch volume.
Apple's bulletin also notes a partial consolation: none of the vulnerabilities in this cycle are listed as being under active exploitation at the time of disclosure.
AI-driven discovery: ten CVEs credited to models and coding agents
Despite the flood of fixes, only ten CVEs in this cycle were credited explicitly to AI-assisted discovery. Two appear in iOS 27 and eight are credited in the macOS 27 notes.
- CVE-2026-65410 (iPhone and iPad AVE video encoders; can cause unexpected system termination) — credited to Calif, Claude, and Anthropic Research.
- CVE-2026-65409 (type-confusion in Foundation; can cause denial of service) — credited to Calif (human researcher Bruce Dang), Claude, and Anthropic Research.
- CVE-2026-43692 (CUPS validation issue; remote termination or code execution) — credited to Aaron Grattafiori and the Nvidia AI Red Team.
- CVE-2026-64790 (CUPS privilege elevation) — credited to Aaron Grattafiori and the Nvidia AI Red Team.
- CVE-2026-43791 (StorageKit validation issue; can be abused to read files) — credited to Grattafiori, the Nvidia AI Red Team, Meridian Miftari, and Amy from amys.website.
- CVE-2026-43690 (SMB race-condition; local user may read kernel memory) — credited to Calif’s Bruce Dang with Claude and Anthropic Research.
- CVE-2026-43719 (SMB use-after-free; mounting a maliciously crafted SMB network share may lead to system termination) — credited to Calif’s Dang, Jakob Pammer, Claude, and Anthropic.
- CVE-2026-65376 (SMB out-of-bounds read) — credited to Dang, Claude, Anthropic, and 재영 정.
- CVE-2026-65374 (WebDAV memory-corruption; can lead to code execution) — credited to Dang, Claude, Anthropic, and He Wei (ギカク).
- CVE-2026-65375 (WebDAV; unexpected system termination) — credited to Dang, Claude, Anthropic, and Devcore Research Team’s YingMuo.
The Register observed the asymmetry: models are becoming “exponentially better and faster at finding security vulnerabilities,” but the promise that models would similarly automate patch-writing has not materialized — "yeah, that hasn't happened yet," the piece put it.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleNotable iOS fixes not tied to AI
Several of the more serious iOS issues in this release were credited to traditional researchers rather than AI assistants. CVE-2026-43689 is a privilege-escalation flaw that could allow an app to gain root access; Apple credited Nosebeard Labs’ Andreas Jaegersberger and Ro Achterberg for that report. CVE-2026-65406 is a logic-issue in Background Assets that could be abused to access sensitive user data; Baidu Security researcher Ye Zhang is credited with that find.
macOS 27: CUPS, SMB and WebDAV vulnerabilities attract attention
macOS 27 Golden Gate consolidates many of the most concerning fixes in this cycle. CUPS — the Common Unix Printing System — figures prominently: CVE-2026-43692 can allow remote termination or code execution, and CVE-2026-64790 can be exploited to gain elevated privileges; both are credited to Aaron Grattafiori and the Nvidia AI Red Team.
Network-file-protocol flaws in SMB and WebDAV are also widespread. The macOS notes include a SMB race-condition (CVE-2026-43690) that a local user can exploit to read kernel memory, SMB use-after-free (CVE-2026-43719) that may cause system termination when mounting a malicious share, and additional SMB out-of-bounds and WebDAV memory-corruption and out-of-bounds write issues (CVE-2026-65376, CVE-2026-65374, CVE-2026-65375, CVE-2026-43677) with a long list of credited researchers.
What this means for technologists, end users, and adversaries
- Technologists and security teams: prioritize deployment of iOS 27 and macOS 27 Golden Gate where compatible; many of the high-severity fixes affect CUPS, SMB, WebDAV and kernel-level components, and multiple researchers and AI-assisted teams reported them. The vendor notes that none are listed as under active exploitation, but many are high-impact if weaponized.
- End users and device owners: the immediate "silver lining" in Apple’s disclosure is that none of the vulnerabilities are currently listed as being under active exploitation; nevertheless, installing updates for iOS 27 and macOS 27 Golden Gate will apply fixes to a large number of issues across phones, tablets and computers.
- Adversaries and offensive researchers: the Register warned that attackers are actively looking to exploit the newly disclosed bugs and that they are “using AI” in that effort, a dynamic mirrored by the small but growing set of AI-credited discoveries in this release.
Apple’s biggest patch day underscores two concurrent realities shown in this cycle: AI is starting to accelerate discovery — ten CVEs here bear that attribution — and disclosure still depends on human coordination and vendor patching. With hundreds of fixes now public and none yet listed as actively exploited, the immediate imperative is straightforward and technical: update devices. The strategic question this episode leaves on the table is whether AI will soon shrink the window between discovery and exploitation or whether defensive tooling will catch up and automate safe, correct remediation at scale — a question grounded in this bulletin’s bluntest line: "that hasn't happened yet."
Original story: https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679




