Apple lists 51 iOS 27 security fixes that aren’t on its iOS 26.7 page

Apple iPhone 18 Pro 2up
Image: Apple

Apple’s security page for iOS 27 lists 51 fixes that its iOS 26.7 page doesn’t, including one for a flaw that could let someone holding your unlocked iPhone see saved Wi-Fi passwords. Apple doesn’t mark any of the 51 as exploited, so this is a reason to plan your upgrade, not to panic.

iOS 27 iPadOS 27
iOS 27 and iPadOS 27, which share a single security content page. Image: Apple

Both pages went up on September 14, the day iOS 27 and iOS 26.7 were released. We compared them entry by entry.

The fixes most owners would notice

Apple sums up each flaw in a one-line Impact statement. These entries appear on the iOS 27 page but not the iOS 26.7 page, in Apple’s words:

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email
  • Wi-Fi (CVE-2026-43674): “An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication.”
  • Shortcuts (CVE-2026-84600): “A malicious shortcut may be able to send messages without user confirmation.”
  • Apple Account (CVE-2026-20683): “An app may be able to use the Sign In With Apple authentication flow to access the user’s Apple Account.”
  • Authentication Services (CVE-2026-86905): “An app may be able to delete credentials stored in Keychain.”
  • MediaRemote (CVE-2026-84628): “A sandboxed app may be able to access the System Keychain.”
  • Safari (CVE-2026-84518): “A malicious website may be able to determine what apps a user has installed.”
  • Telephony (CVE-2026-65329): “An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.” Apple credits researchers at Ruhr University Bochum.
  • CoreMedia (CVE-2026-64752): “Processing a maliciously crafted image may lead to arbitrary code execution.”
  • WebKit (CVE-2026-86898): “Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.”

The Wi-Fi entry is the easiest to picture. Apple’s description needs only physical access to an unlocked iPhone, so it applies to anyone you hand your phone to, and the passwords involved are the ones for the networks you’ve saved, such as home and work. Apple says it fixed the underlying authentication issue “with improved state management.”

The iPad lineup: iPad, iPad Air, iPad Pro and iPad mini side by side.

How we counted

Each of Apple’s security pages is a list of entries. An entry names the part of the system that was fixed, gives the Impact line, and ends with one or more CVE numbers, the standard ID assigned to a single flaw. Some entries carry two or more CVEs, so the entry count and the CVE count differ.

We collected every CVE number from each page, counted each number once, then checked which numbers appear on both pages. The Additional recognition section at the bottom of each page thanks researchers and contains no CVE numbers, so it didn’t affect the totals.

iOS 27 pageiOS 26.7 page
Entries12279
Unique CVE numbers12682
CVE numbers on both pages7575
CVE numbers on this page only517
Entries marked as exploited00

Grouped by Apple’s Impact wording, 31 of the 51 iOS 27-only fixes describe something an app could do, from reading data to escaping its sandbox. Twelve involve opening or processing a booby-trapped image, font, file or web content. Five involve an outside attacker: one with physical access, two on the network and two targeting the baseband, the part of the iPhone that handles cellular connections. The last three are the malicious website, the malicious shortcut and a kernel bug a local user could trigger.

When Apple knows a flaw has been used in attacks, it usually says an issue “may have been exploited.” Neither page contains the word “exploited.”

What iOS 26.7 does fix

iOS 26.7 is a substantial security update. It shares 75 fixes with iOS 27, including some of the most serious on either page. Both list a Bluetooth flaw where “a remote attacker may be able to cause unexpected app termination or arbitrary code execution,” a kernel bug where “a malicious app may be able to gain root privileges,” and a Siri Suggestions issue where “an attacker with physical access to a locked device may be able to view sensitive user information.”

Seven fixes appear only on the iOS 26.7 page: three in ImageIO, and one each in CoreMedia Video Toolbox, IOGPUFamily, Kernel and WebKit. Apple doesn’t explain the gap in either direction. A fix that’s missing from one page isn’t evidence that the other version is exposed, and Apple doesn’t say that iOS 26.7 is affected by the 51 flaws listed only for iOS 27.

Who is on iOS 26.7, and what to do

On iPhone, staying is a choice. Both security pages list “iPhone 11 and later,” so any iPhone that can run iOS 26.7 can also install iOS 27. Apple says it keeps sending security updates to the previous major version “for a period of time” for people who need longer before upgrading. It doesn’t promise that every fix reaches the older branch, and these two pages already differ.

On iPad, some owners have no choice. The iOS 26.7 page covers iPad Pro 12.9-inch (3rd generation), iPad Pro 11-inch (1st generation), iPad Air (3rd generation), iPad (8th generation) and iPad mini (5th generation) and later. The iPadOS 27 page starts one generation later in each line, so those five models get iPadOS 26.7 and not iPadOS 27.

If you’re holding an iPhone back for a reason, such as an app that isn’t ready, pick a date to revisit it rather than waiting indefinitely, and be careful about who handles your phone while it’s unlocked. When you move, our iOS 27 guide covers what changes. If you’re replacing an older iPhone instead, our September event recap covers the new models.