Apple’s release notes for iOS 27 name a new hardware security feature called CPA2, delivered through an instruction set Apple labels arm64e.x1. According to Apple’s own developer documentation, it works only on iPhone models with the A20 Pro chip or later, Mac computers with an M6 chip or later, and Apple Watch models with the S11 chip or later.
That cutoff matters this month. Apple’s own newsroom pages describe two new 2026 Macs, the Mac mini and Mac Studio, that do not share the same chip. The Mac mini’s base configuration uses the new M6, but its upgraded configuration and the entire Mac Studio lineup use M5 Max and M5 Ultra, chips from the generation before M6. Only devices running A20 Pro, M6 or S11 get CPA2 when iOS 27, macOS 27 and watchOS 27 arrive this week.
Key facts
| Item | Detail |
|---|---|
| Feature name | CPA2, enabled through arm64e.x1 |
| Apple’s own description | “additional hardware security and performance instructions, including CPA2 for stronger MIE protection” |
| Qualifying chips | A20 Pro or later (iPhone), M6 or later (Mac), S11 or later (Apple Watch) |
| Where it appears | Apple’s iOS & iPadOS 27 release-candidate release notes, Hardware Security section |
| Developer access | Xcode’s enhanced security pane and a build setting |
| Apple’s internal tracking number | Issue ID 152103975 |
What Apple’s release notes say about CPA2
The feature appears in the Hardware Security section of Apple’s iOS and iPadOS 27 release-candidate release notes, published on Apple’s developer site, under a subsection Apple labels New Features. Apple’s exact wording reads: “arm64e.x1 introduces additional hardware security and performance instructions, including CPA2 for stronger MIE protection. Devices with support for arm64e.x1 include iPhone models with A20 Pro or later chips, Mac computers with M6 or later chips, and Apple Watch models with S11 or later chips.” Apple tracks the entry under issue number 152103975. Apple has not published a matching description of CPA2 on any of its consumer-facing pages for iPhone 18 Pro, Mac mini, Mac Studio or Apple Watch Series 12.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
How CPA2 builds on last year’s Memory Integrity Enforcement
Apple’s notes describe CPA2 as delivering “stronger MIE protection,” tying the new feature to Memory Integrity Enforcement, the always-on memory-safety system Apple detailed in a security research post last year for the A19 and A19 Pro chips inside iPhone 17 and iPhone Air. That earlier post did not mention CPA2, or an M6 or S11 version of the same protection. The iOS 27 release notes are the first place Apple has named a further layer on top of Memory Integrity Enforcement, and the first time Apple has tied a chip-level security instruction set to Mac and Apple Watch silicon by name, rather than iPhone silicon alone.
Which September devices actually qualify
| Device | Chip | Gets CPA2 |
|---|---|---|
| iPhone 18 Pro and iPhone 18 Pro Max | A20 Pro | Yes |
| iPhone Duo | A20 Pro | Yes |
| iPhone 17 and iPhone Air | A19 / A19 Pro | No |
| Mac mini, base configuration | M6 | Yes |
| Mac mini, upgraded configuration | M5 Pro | No |
| Mac Studio (both configurations) | M5 Max or M5 Ultra | No |
| Apple Watch Series 12 and Ultra 4 | S11 | Yes |
Why Mac Studio’s M5 Max and M5 Ultra miss the cutoff
Apple’s own August 25, 2026 Newsroom announcement lists the Mac mini’s chip options as M6 and M5 Pro, and the Mac Studio’s as M5 Max and M5 Ultra. Apple’s iOS 27 release notes set the line for arm64e.x1 support at M6 or later, a bar the base Mac mini clears and the other three configurations do not. That leaves Mac Studio, the more expensive of the two computers in this batch, without the newest named chip-level security instructions when both machines reach stores September 22. Apple has not commented on the gap between the two Macs, and has not said whether a future Mac Studio chip will add support.
How developers turn CPA2 on
Apple’s notes point developers to Xcode, saying access comes through “the enhanced security pane and a build setting.” That places CPA2 in the same category as many release-notes entries: a tool a developer opts an app into, not a setting a person finds inside iOS 27, macOS 27 Golden Gate or watchOS 27’s own menus. Apple has not said whether any of its own apps use the enhanced security pane at launch, or whether third-party apps need a new build, compiled specifically against A20 Pro, M6 or S11 hardware, before the protection applies.
What Apple has not said
Apple has not published a security-research blog post naming CPA2 the way it did for Memory Integrity Enforcement last year, has not described what specific attack class CPA2 defends against beyond “stronger MIE protection,” and has not said whether the feature will extend to the M5 Pro Mac mini, Mac Studio’s M5 Max or M5 Ultra chips, or older Apple silicon in a future software update. The entry also sits inside release-candidate notes, and Apple has not confirmed that it carries over unchanged into the public iOS 27.0 build.
iOS 27, iPadOS 27, macOS 27 Golden Gate and watchOS 27 are all due Monday, September 14, 2026. iPhone 18 Pro, iPhone 18 Pro Max, Apple Watch Series 12 and Apple Watch Ultra 4 reach stores September 18, and Mac mini and Mac Studio follow on September 22, giving developers their first chance to test the enhanced security pane against real A20 Pro, M6 and S11 hardware rather than a beta simulator.