BlackTree Security · Infrastructure · Automation · AI

Apple’s 273-CVE Security Release Includes a Flaw Attackers Have Already Exploited

The Apple security updates released on 14 September are bigger than a single operating-system update. Ten separate advisories cover iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari and Xcode. Across them, Apple lists 1,038 product-level CVE references. Remove the overlap created by shared components and the result is 273 unique vulnerability identifiers.

That is an unusually large attack-surface reset. It is also a number that needs careful handling. Apple did not describe all 273 vulnerabilities as critical, and the total is not a count of 273 newly discovered zero-days. The advisories include everything from privacy and information-disclosure flaws to denial-of-service conditions, sandbox escapes, kernel-level code execution and remote attack paths.

One entry makes the release more urgent than the headline alone suggests. CVE-2026-65400, an authentication bypass in the macOS Screen Sharing Server, is already in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue. It predates this release and was addressed in earlier Apple updates, but it appears again in Apple’s new macOS release advisories. That matters because a fresh operating-system rollout can contain both newly disclosed flaws and known attack paths that organisations may still not have remediated across their estates.

The 273 figure is real, but it is not the whole story

BlackTree independently counted the CVE identifiers in Apple’s ten official advisories. The per-advisory totals add up to 1,038 references, because the same vulnerability can affect several products built on shared frameworks. Deduplicating those references produces 273 unique CVEs.

Apple advisory Unique CVEs listed in that advisory
iOS 27 and iPadOS 27 126
iOS 26.7 and iPadOS 26.7 82
macOS Golden Gate 27 210
macOS Tahoe 26.7 153
macOS Sequoia 15.8 154
tvOS 27 89
watchOS 27 93
visionOS 27 124
Safari 27 6
Xcode 27 1

The overlap is not bookkeeping noise. It is the security consequence of an integrated platform. A flaw in CoreMedia, WebKit, Bluetooth or another shared component can cross several product lines. An organisation that patches its iPhones but postpones Macs, watches, Apple TVs or Vision Pro devices may leave the same underlying weakness active elsewhere.

The exploited Screen Sharing flaw changes the priority order

Apple describes CVE-2026-65400 as an authentication problem that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. CISA added it to the Known Exploited Vulnerabilities catalogue on 18 August 2026 and required US federal agencies to address it by 21 August.

Apple’s September advisories do not repeat an active-exploitation statement. That should not be read as evidence that every vulnerability in this release is unexploited. CISA’s catalogue already establishes exploitation evidence for CVE-2026-65400. The distinction is important: there is no evidence that all 273 vulnerabilities are being exploited, but there is authoritative evidence that at least one vulnerability represented in the release set has been.

BlackTree previously examined how exposed Macs were being hunted after Apple patched the Screen Sharing weakness. Organisations should now use the latest rollout as a second compliance check, not assume that the earlier fix reached every device. Read: Apple Patched Screen Sharing. Internet-Exposed Macs Were Already Being Hunted.

The vulnerabilities defenders should examine first

A raw CVE count cannot determine operational priority. Exposure, privileges, user interaction and the business role of each device matter more than volume. Several entries nevertheless stand out from Apple’s impact statements.

CVE-2026-65400: Screen Sharing authentication bypass

This is the known-exploited item. Apple says an attacker on the network may be able to authenticate to Screen Sharing without valid credentials. Teams should identify Macs with Screen Sharing enabled, confirm that none are unnecessarily reachable from untrusted networks, verify the installed operating-system build and investigate unexplained remote sessions or authentication anomalies. Devices that missed the earlier remediation deserve immediate attention.

CVE-2026-65414: remote code execution through Bluetooth

Apple says a remote attacker may be able to cause an application to terminate or execute arbitrary code through an out-of-bounds write in Bluetooth. The CVE appears across the iOS, iPadOS, macOS, tvOS, watchOS and visionOS advisories. Apple does not say that it is being exploited, but the breadth of affected products and the remote attack wording make it a high-priority validation item.

CVE-2026-84607: kernel-level execution from a sandboxed app

A race condition in AVEVideoEncoder could allow a sandboxed application to execute arbitrary code with kernel privileges. This is the kind of vulnerability that can turn a limited initial foothold into full device compromise. It appears across multiple Apple platforms, so organisations should not restrict validation to one device class.

CVE-2026-64752: malicious image processing can lead to code execution

Apple says processing a maliciously crafted image could lead to arbitrary code execution in CoreMedia. Image and media parsers are attractive attack surfaces because users and applications process untrusted content routinely. The flaw is listed for iOS 27, iPadOS 27, macOS Golden Gate 27 and visionOS 27.

Safari 27: a small list with meaningful web risk

Safari 27 lists only six CVEs, but a low count does not mean low importance. CVE-2026-86898 could allow universal cross-site scripting when a user opens a maliciously crafted webarchive file. CVE-2026-64753 could disclose sensitive information while processing malicious web content. Macs remaining on Sequoia or Tahoe therefore need the Safari update even if the organisation is not yet moving them to macOS 27.

What organisations should do now

  1. Build an affected-device inventory by operating-system branch. Separate devices moving to iOS, iPadOS or macOS 27 from those staying on iOS 26.7, iPadOS 26.7, macOS Tahoe 26.7 or macOS Sequoia 15.8. Apple issued parallel security releases, so a major-version upgrade is not the only remediation route.
  2. Prioritise exposure before counting CVEs. Move Macs with Screen Sharing enabled, internet-facing services, access to external file servers or sensitive administrative roles to the front. Then prioritise systems that routinely process untrusted images, video, archives, fonts, web content or 3D files.
  3. Validate the known-exploited item separately. Search asset and vulnerability data for CVE-2026-65400. Confirm both patch state and service exposure. A dashboard that reports only “latest major version available” is not enough.
  4. Use a rapid test ring, then enforce deployment. Test critical business applications and security tooling on a representative group, but do not let a routine deferral window become an open-ended exception. Apple’s declarative device-management controls can set a target version and enforcement time while reporting whether devices are waiting, downloading, preparing or installing.
  5. Measure build compliance, not user promises. Verify the installed version or build through device management. Track devices that are offline, lack storage, are waiting for a restart or have failed installation.
  6. Treat developer Macs as a separate risk group. Xcode 27 fixes CVE-2026-65393, which could allow an application to access user-sensitive data. Developer endpoints also hold source code, signing material and production credentials, making delayed patching especially costly.
  7. Review unsupported and unmanaged devices. Compare the hardware estate with Apple’s availability lists. Devices outside supported branches should be isolated, replaced or given a formally approved compensating control rather than silently disappearing from compliance reports.

The lesson is not that Apple suddenly became 273 times less secure

Large coordinated releases can make a platform look uniquely vulnerable when the number partly reflects disclosure timing and a shared architecture. The more useful lesson is that a single patch event can touch an organisation’s phones, tablets, laptops, desktops, watches, meeting-room devices, developer tools and spatial-computing hardware at once.

Security teams should resist two equally misleading conclusions. The first is that 273 automatically means 273 critical emergencies. The second is that the absence of a new Apple exploitation warning means the batch can wait. The evidence supports neither view.

The practical response is risk-based and measurable: identify the device branches in use, isolate the known-exploited Screen Sharing weakness, prioritise the remote and kernel-level paths, test quickly, enforce the appropriate release and verify the result. The headline is 273. The job is knowing which of those vulnerabilities can reach which of your devices, and proving that the exposed ones are no longer there.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *