Summary

Apple’s iOS 27 and iPadOS 27 security release, dated September 14, 2026, fixes vulnerabilities across the kernel, WebKit, Bluetooth, media frameworks, privacy controls and other system components.

Apple’s security-content document for iOS 27 and iPadOS 27 lists fixes across core operating-system components, media processing, wireless connectivity, privacy controls and Apple services. The release is dated September 14, 2026, and applies to iPhone 11 and later, along with a range of recent iPad models.

The advisory records vulnerabilities by CVE identifier where possible. Its impact descriptions include unexpected process termination, memory disclosure, unauthorised data access, sandbox escapes and, in some cases, the ability to execute code with elevated privileges.

Fixes reach the kernel, connectivity and media systems

The kernel section contains several fixes for issues that could affect the operating system’s most privileged layer. Apple says one vulnerability could allow a malicious app to gain root privileges. Other entries describe possible kernel-memory corruption, kernel-memory disclosure, unexpected system termination and the ability of a local attacker to read kernel memory.

The listed fixes address several classes of programming and access-control errors. These include out-of-bounds reads and writes, in which software accesses memory outside an intended region; use-after-free issues, where released memory is accessed again; race conditions caused by unsafe interactions between concurrent operations; and permission or authorisation flaws.

Some vulnerabilities involve particular attack conditions. Apple says a malicious NFS server could disclose or corrupt kernel memory, while another issue could allow an app to determine the kernel’s memory layout. A separate Telephony flaw could allow an attacker in a privileged network position to bypass IPSec authentication and intercept network traffic.

Wireless and media components are also covered. In Bluetooth, Apple lists an issue that could allow a remote attacker to cause an app to terminate or execute arbitrary code, as well as an authorisation flaw that could give an app unauthorised Bluetooth access. Two Baseband fixes address issues that could be triggered by an attacker in radio range or by a remote attacker to cause system termination or denial of service.

The AVEVideoEncoder section includes a particularly serious impact description: Apple says a sandboxed app may be able to execute arbitrary code with kernel privileges. Other fixes affect image, video, font, archive, 3D-model and asset-catalog processing. These components handle complex files and data formats, so the advisory repeatedly identifies maliciously crafted files, images, videos, fonts or 3D content as the trigger condition.

Privacy and app-security boundaries are part of the release

The update also targets the boundaries that control what apps can see and do. Apple lists fixes involving sensitive user data, persistent account or device identifiers, installed-app information, location data, protected files and the System Keychain. One iCloud issue could allow an app to identify a user across reinstalls, while flaws in DeviceCheck and Power Management could expose persistent device or hardware information.

Several entries concern privacy preferences and authorisation decisions. The advisory says fixes prevent or restrict apps from accessing motion data from headphones without consent, reading protected files, modifying files they were only allowed to read, and bypassing certain privacy settings. A Symptom Framework issue involved possible exposure of a user’s current location through log entries; Apple says it was addressed with improved private-data redaction.

The release includes changes to user-facing features as well. A malicious shortcut could previously send messages without user confirmation, according to Apple’s impact description. Another issue involving Siri Suggestions could allow an attacker with physical access to a locked device to view sensitive user information.

WebKit, the browser engine used by Safari and other system web views, has four listed issues. Apple says maliciously crafted web content could cause process termination or disclose sensitive information, while opening a malicious webarchive file could lead to universal cross-site scripting. The latter describes a failure in web-content isolation that could allow content from one security context to interact with another unexpectedly.

Apple lists the update for iPhone 11 and later, iPad Pro 12.9-inch models from the 4th generation onward, iPad Pro 11-inch models from the 2nd generation onward, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later. The advisory provides impact descriptions and remediation details for each listed issue, but does not assign severity rankings or state whether any of the vulnerabilities had been exploited before the release.

Sources