A new Apple security update has been dropped for iPhone owners, releasing iOS 26.7 alongside its major annual release, iOS 27. The move gives iPhone users who are hesitant to jump straight into a full system overhaul a safer, lighter-weight path to staying protected, arriving less than a month after the previous patch, iOS 26.6.1.
As is typical with Apple’s security releases, the company has kept details about what iOS 26.7 actually fixes deliberately sparse. The idea is simple: the fewer specifics made public, the less material attackers have to work with before the update reaches the majority of devices.
One of Apple’s Largest Coordinated Patches Yet
This release is part of a much bigger rollout. On September 14, 2026, Apple pushed updates across nearly its entire product line — iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode — through iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27, in addition to iOS and iPadOS 26.7, macOS Tahoe 26.7, and macOS Sequoia 15.8.
In total, the Apple security update resolves 273 unique vulnerabilities. That figure comes from consolidating 1,038 product-level CVE entries spread across ten separate advisories, since many flaws sit in shared frameworks and therefore show up in multiple operating systems at once. macOS Golden Gate 27 accounts for the largest share, with 210 CVEs, followed by macOS Sequoia 15.8 at 154 and macOS Tahoe 26.7 at 153.
Notable Vulnerabilities Addressed
Several of the fixes stand out for their severity. CVE-2026-65414 involved an out-of-bounds write in Bluetooth that could have let a remote attacker crash an app or run malicious code. CVE-2026-84607, a race condition in AVEVideoEncoder, could have allowed a sandboxed app to execute code with kernel-level privileges — both resolved through tighter bounds checking and better state management.
Media handling was another weak point. CoreMedia’s CVE-2026-64752 could have triggered code execution from a maliciously crafted image, while ImageIO’s CVE-2026-65395 risked memory corruption. Apple also patched issues in FontParser, CoreText, CoreUI, SceneKit, RealityKit, Model I/O, and disk-image handling tools.

On the Mac side, fixes targeted privilege-escalation risks in autofs (CVE-2026-84568) and CUPS (CVE-2026-43692), plus a Screen Sharing Server flaw (CVE-2026-65400) that could have let attackers bypass login credentials over a network. Gatekeeper, sandboxing, TCC privacy controls, and file-system protections for SMB, WebDAV, APFS, HFS, and exFAT were all hardened as well.
WebKit received a heavy round of fixes too, with Safari 27 alone patching six CVEs — including one letting cross-site scripting attacks run via a malicious webarchive, and another risking data exposure during web-content processing.
For iPhone specifically, iOS 26.7 closes 16 kernel-level vulnerabilities, the most severe being CVE-2026-43689, which could have granted a malicious app root access. It also fixes five ImageIO bugs and a WebKit use-after-free flaw, CVE-2026-43715, capable of corrupting memory through crafted web content.
Which Update Should iPhone Users Install?
iPhone owners will see iOS 26.7 offered prominently in Settings, with iOS 27 listed as a secondary option — a structure Apple maintains for months after a major release, largely to reassure users and businesses wary of early bugs in new software. iOS 26.7 supports iPhone 11 and later, along with a range of iPad Pro, iPad Air, iPad, and iPad mini models.
Although automatic updates are generally recommended, Apple’s staged rollout can take days or weeks to reach every device, so security specialists suggest installing iOS 26.7 manually via Settings > General > Software Update.

