The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino's history.
While this CVE count is hardly notable compared to some vendors - hello, Microsoft’s record-breaking 974 bugs disclosed earlier this month - it does set a company record for Apple.
It also reflects the new reality of AI-driven bug hunting, as models become exponentially better and faster at finding security vulnerabilities.
However, the flip side of the AI coin we were promised - that models would also excel at writing patches and automatically fixing software and systems - yeah, that hasn't happened yet.
The silver lining for everyone updating their Apple products right now (including this humble vulture): none of the vulnerabilities are listed as being under active exploitation.
Of course, that may change very quickly as attackers are, at this very moment, looking to exploit the newly disclosed bugs, too.
And we promise you that they are using AI.
Apple’s latest mobile and operating system versions, iOS 27 and macOS 27 Golden Gate, released on Monday, also address a record 122 and 204 security vulnerabilities, respectively, across phone, iPad, and computer operating systems.
Of these hundreds of CVEs, however, there are only ten (by our count) that AI is directly credited with finding. iOS 27 fixes 122 flaws Just two of the iPhone and iPad CVEs fixed with iOS 27 credit a coding agent or AI assistant with finding them.
These include CVE-2026-65410, a vuln that exists in iPhone and iPad AVE video encoders, that can cause unexpected system termination.
Apple credited AI-bug-finding firm Calif, along with Claude and Anthropic Research, with finding and reporting this security flaw.
Then there's CVE-2026-65409, a type-confusion issue in iOS’ Foundation framework that can be abused to cause a denial of service, also found by Calif - specifically human researcher Bruce Dang - in collaboration with Claude and Anthropic Research.
Some of the more interesting and serious iOS bugs fixed with the newest update aren’t listed as found by AI.
These include CVE-2026-43689, a privilege-escalation flaw that could allow an app to gain root access.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.