The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
Apple has released iOS 27 and macOS 27 "Golden Gate," patching more than 260 CVEs across its operating systems and software in what marks the largest single patch cycle in the company's history. The record haul is being attributed to the growing use of AI-driven bug hunting, which is rapidly accelerating vulnerability discovery even though AI has yet to prove similarly useful at automatically writing fixes. None of the flaws are currently listed as being actively exploited, though that could change quickly now that details are public.
iOS 27 fixes 122 vulnerabilities and macOS 27 fixes 204, though only around ten across both platforms are credited to AI tools such as Claude and Anthropic Research, working alongside firms like Calif and the Nvidia AI Red Team. Notable bugs include CVE-2026-43689, a privilege-escalation flaw allowing root access; CVE-2026-43692, a CUPS printing flaw enabling remote code execution; and CVE-2026-43690 and CVE-2026-43719, SMB-related bugs that could expose kernel memory or crash a system via a malicious network share.
- Apple patches record 260+ CVEs in iOS 27 and macOS 27
- AI tools like Claude helped find about ten of the bugs
- No flaws are currently known to be actively exploited