Author Topic: iOS 27 fixes 122 security vulnerabilities, including serious kernel flaws  (Read 38 times)

Offline javajolt

  • Administrator
  • Hero Member
  • *****
  • Posts: 36084
  • Gender: Male
  • I Do Windows
    • windows10newsinfo.com
Apple fixed 122 security vulnerabilities in iOS 27. Some of the most serious ones could give attackers root access and hijack network traffic.



Apple just released iOS 27 to the public. And while the focus of the majority of users is directed towards new features and UI refinements, the latest major iOS update brings something arguably more important. Namely, Apple has shipped more than 100, or 122 to be precise, fixes for various vulnerabilities across iPhones and iPads.

Apple shared details about the fixes in its latest security advisory, covering everything from the kernel and WebKit to Safari, Siri, storage, authentication, and privacy-related components. Some of the vulnerabilities are relatively minor, but others could have had much more serious consequences.

One of the more important fixes addresses CVE-2026-43689 in the kernel. According to Apple, a malicious app could exploit the flaw to get root privileges, which would essentially give it the highest level of access on the system. Apple says it fixed the permissions issue by adding "additional restrictions."

There’s also CVE-2026-84523 in APFS, Apple's file system. That vulnerability could allow an app to unexpectedly terminate the system or write kernel memory. Apple addressed the out-of-bounds write issue with "improved bounds checking."

Another notable fix is CVE-2026-65329 in Telephony. Apple says an attacker in a privileged network position could potentially bypass IPSec authentication and intercept network traffic, which could allow threat actors to access users’ browsing data. Apple’s fix for this issue was "improved state management."

The update also fixes a wide range of other problems, including WebKit vulnerabilities, privacy issues that could expose sensitive user data, and flaws that could let apps identify other installed apps or bypass certain restrictions. There’s even a Shortcuts bug that could allow a malicious shortcut to send messages without confirmation from the user.

If you take a look at the advisory, you'll notice that Apple mostly gives brief explanation on what was done with certain vulnerability, without going too much details. So we couldn't give you more details beyond what was said by Apple.

We’ve already reported that Apple is increasingly relying on AI to hunt for vulnerabilities, and the iOS 27 batch is no exception. Most notably, Apple credited help from both OpenAI and Anthropic in the advisory. One vulnerability was discovered by Calif.io in collaboration with Claude and Anthropic Research, and a few were discovered by Codex Security.

If you want to check out every vulnerability that the company addressed in iOS 27, visit Apple’s official security advisory.

source