Description:
Apple has released iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, Safari 27, tvOS 27, visionOS 27, watchOS 27 and Xcode 27 to fix the vulnerabilities in various Apple devices. The list of vulnerabilities information can be found at:
https://support.apple.com/en-us/149034
https://support.apple.com/en-us/149035
https://support.apple.com/en-us/149036
https://support.apple.com/en-us/149037
https://support.apple.com/en-us/149038
https://support.apple.com/en-us/149039
https://support.apple.com/en-us/149040
https://support.apple.com/en-us/149041
https://support.apple.com/en-us/149042
https://support.apple.com/en-us/149043
Reports indicated that a security restriction bypass vulnerability (CVE-2026-65400) is being exploited in the wild. In addition, reports indicated that proof-of-concept (PoC) exploit code is publicly available for a denial of service vulnerability (CVE-2026-34979) and an information disclosure vulnerability (CVE-2026-43760). System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
Affected Systems:
- iPhone XS and later, iPhone 11 and later
- iPad 8th generation and later, 9th generation and later, Air 3rd generation and later, 4th generation and later, mini 5th generation and later, 6th generation and later, Pro 11-inch 1st generation and later, 2nd generation and later, Pro 12.9-inch 3rd generation and later, 4th generation and later
- macOS Sequoia prior to version 15.8
- macOS Tahoe prior to version 26.7
- macOS Golden Gate prior to version 27
- visionOS prior to version 27
- Safari prior to version 27
- tvOS prior to version 27
- watchOS prior to version 27
- Xcode prior to version 27
Impact:
Depending on the vulnerabilities exploited, a successful attack could lead to remote code execution, denial of service, elevation of privilege, information disclosure, security restriction bypass, spoofing or tampering on an affected system.
Recommendation:
Patches for affected products are available. Users of affected systems should follow the recommendations provided by the vendor and take immediate actions to mitigate the risk.
The updates can be obtained through the auto-update mechanism. Users of affected systems should follow the recommendations provided by the vendor and take immediate actions to mitigate the risk.
More Information:
- https://support.apple.com/en-us/149034
- https://support.apple.com/en-us/149035
- https://support.apple.com/en-us/149036
- https://support.apple.com/en-us/149037
- https://support.apple.com/en-us/149038
- https://support.apple.com/en-us/149039
- https://support.apple.com/en-us/149040
- https://support.apple.com/en-us/149041
- https://support.apple.com/en-us/149042
- https://support.apple.com/en-us/149043
- https://www.hkcert.org/security-bulletin/apple-products-multiple-vulnerabilities_20260915
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3437
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20683
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28899
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28930
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28934 (to CVE-2026-28935)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28966
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28968 (to CVE-2026-28969)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34979
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43661
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43664
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43677
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43683 (to CVE-2026-43684)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43686 (to CVE-2026-43692)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43695
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43697 (to CVE-2026-43698)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43702
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43715
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43719
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43737 (to CVE-2026-43738)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43741
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43743
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43760
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43763
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43785 (to CVE-2026-43787)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43789 (to CVE-2026-43791)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43794 (to CVE-2026-43795)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64712
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64715
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64718
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64736
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64752 (to CVE-2026-64753)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64756
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64758
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64760 (to CVE-2026-64761)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64778 (to CVE-2026-64782)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64784
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64787 (to CVE-2026-64788)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64790
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65330 (to CVE-2026-65349)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65351
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65354
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65358 (to CVE-2026-65362)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65364 (to CVE-2026-65365)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65369
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65371
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65374 (to CVE-2026-65378)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65381 (to CVE-2026-65382)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65390 (to CVE-2026-65391)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65393
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65395
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-65398 (to CVE-2026-65415)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84487
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84489
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84491 (to CVE-2026-84492)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84497
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84505 (to CVE-2026-84507)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84509 (to CVE-2026-84527)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84530
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84532 (to CVE-2026-84538)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84540 (to CVE-2026-84541)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84543 (to CVE-2026-84544)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84546
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84548 (to CVE-2026-84556)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84559 (to CVE-2026-84561)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84563 (to CVE-2026-84568)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84570 (to CVE-2026-84578)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84580 (to CVE-2026-84581)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84583 (to CVE-2026-84584)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84586 (to CVE-2026-84587)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84593
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84596 (to CVE-2026-84598)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84600 (to CVE-2026-84603)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84606 (to CVE-2026-84607)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84609
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84611 (to CVE-2026-84612)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84615 (to CVE-2026-84626)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84628 (to CVE-2026-84632)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84635 (to CVE-2026-84636)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86869 (to CVE-2026-86870)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86876
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86878 (to CVE-2026-86879)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86881 (to CVE-2026-86893)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86895
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86897 (to CVE-2026-86898)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86900 (to CVE-2026-86901)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86903 (to CVE-2026-86905)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86910
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86917
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86924