Apple iOS/iPadOS 27, macOS Tahoe 26.7 / Sequoia 15.8, Safari 27 security content (14 Sep 2026)
Apple published security-content pages dated 14 September 2026 for major releases including iOS 27 and iPadOS 27 (support.apple.com/en-us/149034; 100+ CVE entries on that page alone), macOS Tahoe 26.7 (149042), macOS Sequoia 15.8 (149043), Safari 27 (149039), plus tvOS/watchOS/visionOS 27 and macOS Golden Gate 27. Highlighted iOS 27 entries (Apple does not publish CVSS): sandbox breakout CVE-2026-65354; sandboxed app to kernel privileges CVE-2026-84607; WebKit universal cross-site scripting via crafted webarchive CVE-2026-86898; ImageIO/remote code-execution class issues including CVE-2026-65414; privileged-network IPSec authentication bypass CVE-2026-65329 (also listed on earlier 26.6.x content). No “actively exploited” callouts observed on the fetched iOS 27 page. UPDATE 16 September 2026 desk: macOS Golden Gate 27 security content (support.apple.com/en-us/149035) re-fetched — 200+ CVE entries on that page alone; SecurityWeek wire summarised ~200 fixes across the iOS 27 / Golden Gate 27 family. Primary remains Apple iOS/iPadOS 27; Golden Gate URL retained as secondary. Separate from prior desk card apple-ios-2661-20260817.
- Product
- Apple iOS, iPadOS, macOS Tahoe/Sequoia, Safari (also tvOS/watchOS/visionOS 27)
- Versions
- iPhone 11 and later; listed iPad models; macOS Tahoe 26.7 / Sequoia 15.8; Safari 27 on Sequoia/Tahoe
- Exploited in Australia?
- unknown
- Patch to
- iOS/iPadOS 27 (or current security update for your train); macOS Tahoe 26.7 / Sequoia 15.8; Safari 27
Primary: Apple: iOS 27 and iPadOS 27 security content (14 Sep 2026) · Vendor: Apple security releases index · CVE: CVE-2026-65354, CVE-2026-84607, CVE-2026-86898, CVE-2026-65414, CVE-2026-65329 · Apple: macOS Golden Gate 27 security content (200+ CVEs on page)
