Apple released iOS 27 and iPadOS 27 on September 14, 2026, with a security bulletin listing more than 120 entries. The fixes cover serious problems across the operating systems, including possible arbitrary code execution, kernel or root privilege escalation, sandbox escapes, sensitive-data exposure, privacy bypasses, authentication failures, network interception and denial-of-service conditions.

The US rollout also began on September 14 for compatible iPhones. Here is what the update covers, which devices are eligible and how it relates to the parallel iOS 26.7 and iPadOS 26.7 releases.

More than 120 security entries across iOS 27 and iPadOS 27

The headline figure refers to more than 120 security entries in Apple’s bulletin. It is not presented as a separately deduplicated total of unique vulnerabilities across the two operating systems.

The impact varies by component and operating conditions. Some fixes address flaws that could allow malicious code to run, while others concern access to protected data, system privileges, privacy controls, authentication or network traffic.

Apple’s descriptions include issues that could let a malicious app gain root privileges, disclose or corrupt kernel memory, or determine the kernel’s memory layout. In other cases, the fixes address sandbox escapes, credential deletion, privacy bypasses and denial-of-service conditions.

WebKit—the browser engine used by Safari and other browser experiences on Apple platforms—also receives fixes. They address malicious web content, a crafted web archive capable of universal cross-site scripting, Safari crashes and sensitive-information disclosure.

Which attacks and components are covered?

The bulletin spans a wide set of system components rather than a single security subsystem. The practical effects described by Apple include:

  • Code execution: specially crafted content or files could cause code to run under particular conditions.
  • Privilege escalation: a malicious app could potentially obtain kernel or root privileges.
  • Sandbox escapes: code could cross the isolation boundary intended to contain an app.
  • Data exposure: flaws could disclose sensitive information or kernel memory.
  • Privacy and authentication bypasses: some fixes address unauthorized access to protected functions or information.
  • Network and denial-of-service problems: other entries concern traffic interception, crashes or conditions that make a service unavailable.

These categories describe different entries and conditions; a single fix does not necessarily involve every impact listed above.

Devices covered by the iOS 27 and iPadOS 27 bulletin

Apple lists the following compatibility range for the September 14 releases:

SystemCovered devicesRelease dateSecurity scope
iOS 27iPhone 11 and laterSeptember 14, 2026More than 120 security entries across the iOS 27 and iPadOS 27 bulletin, including kernel, WebKit, privacy and code-execution fixes
iPadOS 27iPad Pro 12.9-inch, 4th generation and later; iPad Pro 11-inch, 2nd generation and later; iPad Air, 4th generation and later; iPad, 9th generation and later; iPad mini, 6th generation and laterSeptember 14, 2026More than 120 security entries across the iOS 27 and iPadOS 27 bulletin, including kernel, WebKit, privacy and code-execution fixes

The compatibility floor means that iPhone models before iPhone 11 are outside Apple’s listed iOS 27 range. For iPadOS 27, the generation matters: the supported families begin at the iPad Pro 12.9-inch 4th generation, iPad Pro 11-inch 2nd generation, iPad Air 4th generation, iPad 9th generation and iPad mini 6th generation.

iOS 26.7 and iPadOS 26.7 follow a separate branch

Apple released iOS 26.7 and iPadOS 26.7 on the same date as the major-version updates. Those releases provide a security-update path for people remaining on the previous major software branch.

The older-branch bulletins include fixes involving ImageIO, Kernel, IOGPUFamily, CoreMedia Video Toolbox and WebKit. They are separate releases with their own security contents, rather than a single package shared with iOS 27 and iPadOS 27.

For users with a compatible device, the choice is therefore between moving to the new major branch or remaining on the previous branch with its separate 26.7 security update. Apple’s published entries identify the components addressed in each release.