The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

5 hours ago 11

Security

September Patch Tuesday part 2?

Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino's history. 

While this CVE count is hardly notable compared to some vendors - hello, Microsoft’s record-breaking 974 bugs disclosed earlier this month - it does set a company record for Apple. It also reflects the new reality of AI-driven bug hunting, as models become exponentially better and faster at finding security vulnerabilities.

However, the flip side of the AI coin we were promised - that models would also excel at writing patches and automatically fixing software and systems - yeah, that hasn't happened yet.

The silver lining for everyone updating their Apple products right now (including this humble vulture): none of the vulnerabilities are listed as being under active exploitation. Of course, that may change very quickly as attackers are, at this very moment, looking to exploit the newly disclosed bugs, too. And we promise you that they are using AI.

Apple’s latest mobile and operating system versions, iOS 27 and macOS 27 Golden Gate, released on Monday, also address a record 122 and 204 security vulnerabilities, respectively, across phone, iPad, and computer operating systems.

Of these hundreds of CVEs, however, there are only ten (by our count) that AI is directly credited with finding.

iOS 27 fixes 122 flaws

Just two of the iPhone and iPad CVEs fixed with iOS 27 credit a coding agent or AI assistant with finding them. These include CVE-2026-65410, a vuln that exists in iPhone and iPad AVE video encoders, that can cause unexpected system termination. Apple credited AI-bug-finding firm Calif, along with Claude and Anthropic Research, with finding and reporting this security flaw.

Then there's CVE-2026-65409, a type-confusion issue in iOS’ Foundation framework that can be abused to cause a denial of service, also found by Calif - specifically human researcher Bruce Dang - in collaboration with Claude and Anthropic Research.

Some of the more interesting and serious iOS bugs fixed with the newest update aren’t listed as found by AI.

These include CVE-2026-43689, a privilege-escalation flaw that could allow an app to gain root access. Apple credited Nosebeard Labs’ Andreas Jaegersberger and Ro Achterberg with reporting this bug.

Additionally, CVE-2026-65406, a logic-issue flaw due to improper validation in Background Assets, could be abused to access sensitive user data. Background Assets is an Apple framework that lets you download large files and content in the background before a user opens the app for the first time. Baidu Security researcher Ye Zhang spotted this one.

macOS 27 patches 204 vulns

Meanwhile, the new macOS 27 update that addresses 204 vulns also fixes both the AI hunted bugs: CVE-2026-65410 and CVE-2026-65409. Plus, it credits AI helpers with discovering eight others, including one especially nasty flaw that could lead to remote code execution through the CUPS printer interface. Let’s start with that one.

CVE-2026-43692 is a validation issue in CUPS that can be exploited by a remote user to either terminate the app or execute malicious code. Aaron Grattafiori and the Nvidia AI Red Team receive credit for disclosing this flaw.

CVE-2026-64790 in CUPS can be exploited to gain elevated privileges. Grattafiori and the Nvidia AI Red Team again get credit for the win.

CVE-2026-43791, a validation issue in StorageKit, can be abused to read files. Grattafiori, the Nvidia AI Red Team, Meridian Miftari, and Amy from amys.website disclosed this flaw to Apple.

CVE-2026-43690 is a race-condition bug in the Server Message Block (SMB) network communication protocol. A local user can exploit the flaw to read kernel memory. Calif’s Bruce Dang, with Claude and Anthropic Research, found this one.

CVE-2026-43719 is another SMB use-after-free bug, discovered by Calif’s Dang and Jakob Pammer, Claude, and Anthropic. “Mounting a maliciously crafted SMB network share may lead to system termination,” Apple warned. 

CVE-2026-65376 is yet another SMB issue - this one an out-of-bounds-read flaw reported by Dang, Claude, Anthropic, and 재영 정.

CVE-2026-65374 is a memory-corruption issue in the WebDAV protocol that can lead to code execution. Dang, Claude, Anthropic, and He Wei (ギカク) receive credit for finding this bug.

CVE-2026-65375, also in WebDAV, can cause unexpected system termination. Apple credited Dang, Claude, Anthropic, and Devcore Research Team’s YingMuo.

CVE-2026-43677 is an out-of-bounds write issue in WebDAV with a slew of researchers receiving credit for finding it. In addition to the usual trio (Dang, Claude, and Anthropic), bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard Zana, Chris Bailey - Short Circuit, Aswin Kumar Gokulakannan, and Surya Narayan Kushwaha are on the list.®

Read Entire Article