Apple shipped iOS 27 and iPadOS 27 on September 14, 2026, closing out about 126 security flaws in one release, 20 of them in the kernel, the core layer that can hand an attacker control of the entire operating system if the flaw is exploited. The most severe of the batch lets a maliciously crafted image trigger arbitrary code execution as soon as a device processes it, meaning opening or even previewing the image can be enough. Millions of iPhones will never receive that fix: Apple’s own device-compatibility page caps several older models on iOS versions the company stopped patching for anything but the most urgent flaws years ago.
A CoreMedia Bug Worth 7.3 on the Severity Scale
The flaw lives in CoreMedia, the framework Apple’s operating systems use to decode audio and video, and Apple’s own advisory describes it as a memory-corruption issue that engineers fixed by removing the vulnerable code outright rather than patching around it. An attacker who gets a single crafted image in front of a target does not need that person to install anything or grant any special permission for the code to run.
Independent vulnerability trackers rate the flaw, filed as CVE-2026-64752, at 7.3 on the ten-point CVSS severity scale, in the high range. Apple’s own security notes for the release confirm that processing a maliciously crafted image may lead to arbitrary code execution, the exact mechanism Adam Boynton, senior enterprise strategy manager at the device-management company Jamf, pointed to when he said “an attacker could compromise an iPhone by getting a malicious image in front of the user.”
Twenty Kernel Fixes and the Rest of the List
Twenty of the roughly 126 fixes touch the kernel, the layer of the operating system that manages memory and hardware access for every app on the device; a working kernel exploit is generally the difference between an attacker trapped inside a single app’s sandbox and one who controls the whole phone. The list beyond CoreMedia includes a race condition in the AVEVideoEncoder component that could let a sandboxed app execute code at the kernel level, an out-of-bounds write in the RealityKit augmented-reality engine triggered by a malicious 3D file, a Bluetooth flaw reachable without physical access to the device, and a certificate-validation bypass that could let a compromised intermediate authority impersonate a trusted one and intercept traffic a user believes is encrypted end to end.
Apple’s advisory for CVE-2026-64752 does not name an outside researcher or security firm as the finder, a common pattern for flaws discovered through internal review rather than reported through the company’s bug-bounty program. The absence of a named finder does not make the flaw less serious; it still carries the same 7.3 severity score and the same image-processing trigger regardless of who discovered it first.
Security researchers who tallied the release count about 126 security flaws fixed in iOS 27 and iPadOS 27, alongside a much larger simultaneous patch covering macOS, tvOS, watchOS and visionOS.
The iPhones iOS 27 Was Never Built For
Apple’s own device-compatibility page shows which iPhones the update reaches and which it does not. The iPhone 8, iPhone 8 Plus and iPhone X are capped at iOS 16.7.16, a branch Apple stopped feature-patching years ago, while the iPhone 6s and iPhone 7 stop at iOS 15.8.8 and the iPhone 6 and iPhone 6 Plus stop at iOS 12.5.8.
Apple’s newest iPhones, from the iPhone 11 onward, run the same iOS 27 build carrying every fix in the release, while an iPhone 8 sold only a few years earlier is locked out of all of them, including the CoreMedia fix the company itself rates as capable of full code execution.
A Wider Patch Cycle Across Every Apple Platform
iOS 27 arrived as part of a coordinated release Apple runs across its whole product line, tracked on the company’s own list of security releases. The same week brought macOS Golden Gate 27, which carried roughly 210 fixes of its own, about 100 of them shared with the iOS 27 patch, plus separate updates for tvOS 27, watchOS 27 and visionOS 27.
Apple also patched two older Mac operating systems that same day for machines too old to run Golden Gate 27 at all: macOS Tahoe 26.7 received 153 unique CVE fixes, including 26 kernel-level defects, and macOS Sequoia 15.8 received more than 150 fixes of its own. Safari 27 and Xcode 27 rounded out the release with six fixes and one fix, respectively, small numbers next to the phone and Mac totals but part of the same coordinated release day.
None of those companion releases reach the iPhones stuck on iOS 16.7.16, 15.8.8 or 12.5.8, the versions Apple will keep alive only long enough to patch whatever a future flaw makes unavoidable, not to add the fixes that shipped everywhere else on September 14.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Early electric-car owners are hitting battery and screen failures no one warned them about
- A magnitude 5.3 quake struck off the Oregon coast this week
- Amazon’s Prime refunds are rising to $200 as millions more customers become eligible
- A handful of car engines are so tough mechanics say they almost never wear out