HeadlinesBriefing favicon HeadlinesBriefing.com

iOS 27 and iPadOS 27 Security Fixes: Full List

9to5Mac •
×

Apple has detailed the security fixes included in iOS 27 and iPadOS 27, released today. The updates address more than 120 vulnerabilities, some allowing arbitrary code execution, kernel or root privileges, sensitive data access, and bypassing system protections.

Affected devices include iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later.

Notable CVEs include CVE-2026-86882 (out-of-bounds write in Accelerate Framework, credited to Peter Malone), CVE-2026-43664 (Accessibility data access, credited to Stuart Wallace, Ilya Andr (andrd3v), Rosyna Keller of Totally Not Malicious Software, CJ Vana, David Strnadel, Daniel Febrero, Asaf Cohen, Gongyu Ma (@Mezone0), and Jian Lee (@speedyfriend433)), CVE-2026-64761 (app identification, credited to Stuart Wallace and Sindre Sorhus), CVE-2026-65404 (privacy bypass, credited to Arni Hardarson (Neonix Security), Vinay Kumar Rasala (Xplo8E) from Appknox, Stuart Wallace, and 이재영), and CVE-2026-84523 (kernel memory write, credited to Cem Onat Karagun and an anonymous researcher). The App Store also received a fix for a persistent account identifier issue.