With the release of iOS 27, Apple has made significant improvements. The list ranges from the kernel and Bluetooth to the camera and includes vulnerabilities that could grant root access to an app. Those who don't want to upgrade to the new version will also receive most of the fixes in iOS 26.
Apple publishes a separate security document for each system version, and the one for iOS 27 and iPadOS 27 is unusually long. It's dated September 14th, the day the entire system series was released. It lists entries ranging from the Accelerate Framework to XPC – covering everything from the kernel and network stack to media codecs, sandboxing, and accessibility features.
Key Facts at a Glance
- The fixes apply to iPhone 11 and newer, as well as iPads from the 9th generation onwards.
- These include several kernel bugs, one of which could grant root privileges to a malicious app.
- A Bluetooth vulnerability allowed the remote execution of arbitrary code.
- Apple does not indicate in any of the entries that the vulnerability has already been exploited.
- Those who want to stay on iOS 26 will receive most of the fixes with iOS 26.7.
The four most sensitive entries
| Area | What was possible |
|---|---|
| Kernel | A malicious app was able to gain root privileges. |
| Bluetooth | A remote attacker was able to execute foreign code. |
| Telephony | An attacker in the network path was able to bypass IPSec authentication and intercept data traffic. |
| Wi-Fi | With physical access to an unlocked device, Wi-Fi passwords could be read without authentication. |
The Bluetooth vulnerability is the one that requires the least effort from the victim: it doesn't require an installed app or any clicks, but rather radio range. Two similar vulnerabilities exist in the mobile network baseband, which could be used to crash a device within radio range.
A second block concerns not so much the takeover of the device as spying: Several fixes prevent apps from reading persistent identifiers, querying the device name, recognizing installed apps, or recognizing users across a reinstallation.
Who reported the gaps
Apple's list of acclaimed institutions this time features a striking number of European research institutions. The workaround for IPSec authentication was developed by a team at Ruhr University Bochum. Among the other acknowledgments, a group from Graz University of Technology, together with the Interdisciplinary Transformation University, is mentioned for their contribution to a vulnerability in the mDNSResponder network service.
In addition, there are security departments of large corporations, university laboratories from South Korea and Japan, and a long list of individual researchers.
AI tools are now listed in the acknowledgments.
Apple explicitly cites two entries as the result of a collaboration with Claude and Anthropic Research, discovered by a security service provider: a flaw in the video encoder and a type error in the Foundation framework. The acknowledgments for WebKit also include an entry from OpenAI Codex Security.
This remains a marginal number compared to the dozens of reports submitted by individuals. What is remarkable is the way it's presented: Apple doesn't list the tools as background aids, but rather names them alongside the people who submitted the findings.
Those who want to stay on iOS 26
Alongside the new generation, Apple has released a security update for iOS 26.7. A large portion of the fixes are included in both versions – so those who want to wait before switching to the new interface are not left unprotected.
For older devices, this is the only option anyway: iOS 27 requires at least an iPhone 11. If the update gets stuck or fails with an error message, the usual troubleshooting steps for update problems should help – Apple's servers are typically overloaded on the release day.
Why this update counts even without the new features
The scope far exceeds that of a typical point update: the last security update in the 26 series closed 29 vulnerabilities, while this one addresses many times that number. This is inherent to a generational leap, which culminates in a year of research.
In practical terms, this means that as long as a vulnerability remains unpublished, it offers little benefit to attackers. This changes once the documentation is published, as it details the scope, type of flaw, and its impact. Therefore, the critical period is the time between release and installation – not whether a vulnerability has been exploited beforehand.
While some features are missing in the EU version, the security level is fully intact. This part of the update is being rolled out in full here.
Do you update on the release date, or do you prefer to wait a week or two until the first bug reports are in? Let us know in the comments how you handle major version jumps.



