Apple's iOS and macOS 27 Bring Major Security Overhaul, Patch Over 300 Flaws
Apple has released iOS 27 and macOS 27, bringing a large batch of security fixes alongside new enterprise controls. iOS 27 addresses 122 vulnerabilities, while macOS 27 fixes more than 200, including issues with memory corruption, privilege escalation, kernel memory access and remote code execution. Some of these bugs were identified with help from AI systems such as Anthropic's Claude and OpenAI's Codex Security.
Beyond patching, Apple has tightened enterprise security controls. Organisations using Platform Single Sign-On can now require Touch ID or an Apple Watch alongside a password on supervised Macs, and Platform SSO now supports web-based authentication and QR code login flows. Apple has also retired legacy update management tools, meaning organisations must now use declarative management to enforce updates. New declarative controls also let administrators allow or deny specific executable binaries based on code-signing properties, with Apple's Endpoint Security framework able to terminate blocked processes.
The update also addresses an AI-specific security issue: a bug in Apple Intelligence that allowed an application to bypass security prompts has been fixed through improved state management, reflecting growing attention to security risks introduced by AI features.