LIVE · cybersecurity feed
Live wire
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

zeroday.news ·

Photo: Daniel L. Lu (user:dllu) (CC BY-SA 4.0) via Wikimedia Commons

Apple has released a substantial security update across its operating systems and software, addressing over 260 Common Vulnerabilities and Exposures (CVEs). This marks the largest single patch cycle in the company's history. While no vulnerabilities are currently reported as being under active exploitation, the disclosure of these flaws often prompts attackers to attempt to exploit them.

The updates include iOS 27 and macOS 27 Golden Gate, which were released on Monday. iOS 27 resolves 122 security vulnerabilities affecting iPhones and iPads, while macOS 27 addresses 204 vulnerabilities across Mac computers.

Among the hundreds of patched CVEs, Apple has credited artificial intelligence (AI) with the discovery of ten. Two of these AI-discovered flaws affect both iOS and macOS: CVE-2026-65410, a vulnerability in AVE video encoders that could cause unexpected system termination, and CVE-2026-65409, a type-confusion issue in the Foundation framework that could lead to a denial of service. Both were reported by Calif, in collaboration with Claude and Anthropic Research, with human researcher Bruce Dang specifically noted for CVE-2026-65409.

Additional AI-assisted discoveries in macOS 27 include several critical vulnerabilities. CVE-2026-43692, a validation issue in the CUPS printer interface, could allow a remote user to terminate an application or execute arbitrary code. CVE-2026-64790, also in CUPS, could lead to elevated privileges. Aaron Grattafiori and the Nvidia AI Red Team are credited with disclosing both of these CUPS flaws.

Other AI-identified issues in macOS include CVE-2026-43791, a StorageKit validation issue that could allow file reading, reported by Grattafiori, the Nvidia AI Red Team, Meridian Miftari, and Amy from amys.website. Several vulnerabilities were found in the Server Message Block (SMB) network communication protocol: CVE-2026-43690, a race-condition bug allowing local users to read kernel memory, reported by Calif's Bruce Dang with Claude and Anthropic Research; CVE-2026-43719, an SMB use-after-free bug discovered by Calif's Dang and Jakob Pammer, Claude, and Anthropic, which could lead to system termination when mounting a malicious SMB share; and CVE-2026-65376, an out-of-bounds-read flaw reported by Dang, Claude, Anthropic, and 재영 정.

The WebDAV protocol also had several AI-discovered vulnerabilities patched in macOS. CVE-2026-65374, a memory-corruption issue, could lead to code execution, reported by Dang, Claude, Anthropic, and He Wei (ギカク). CVE-2026-65375 could cause unexpected system termination, credited to Dang, Claude, Anthropic, and Devcore Research Team’s YingMuo. CVE-2026-43677, an out-of-bounds write issue, was reported by a larger group including Dang, Claude, Anthropic, bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard Zana, Chris Bailey - Short Circuit, Aswin Kumar Gokulakannan, and Surya Narayan Kushwaha.

Beyond the AI-assisted discoveries, other significant vulnerabilities were addressed. In iOS 27, CVE-2026-43689 is a privilege-escalation flaw that could grant an application root access, reported by Nosebeard Labs’ Andreas Jaegersberger and Ro Achterberg. CVE-2026-65406, a logic issue in Background Assets due to improper validation, could allow access to sensitive user data and was reported by Baidu Security researcher Ye Zhang.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s