If your iPhone has been nagging you about a software update since mid-September, there's a good reason to stop postponing it. Apple's September 2026 release — anchored by iOS/iPadOS 27 — wasn't just a version bump with new features. It shipped alongside one of the largest coordinated security patches Apple has ever released, and at least one of the bugs it fixes was already being used in real attacks before the patch landed.
Table of Contents
What Actually Shipped
Apple's September 2026 security releases covered essentially every product line at once: iOS/iPadOS 27, iOS/iPadOS 26.7 (a parallel patch for devices not moving to the new major version), macOS 27 "Golden Gate," macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27, tvOS 27, Safari 27, and Xcode 27. Across all of it, Apple addressed 273 distinct CVEs — a scale that reflects both a major annual OS release and the accumulated backlog of issues found by internal teams, external researchers, and bug bounty submissions over the year.
Most of these 273 issues are routine: memory-safety bugs, logic errors, and information-disclosure flaws that require specific and often difficult-to-achieve conditions to exploit. A small handful are not routine at all.
The Bugs Worth Knowing About
Three vulnerabilities in this release stand out from the rest, either because of their severity score, their reach across platforms, or confirmation that they were already being exploited:
| CVE | Component | Severity | Why it matters |
|---|---|---|---|
| CVE-2026-65400 | Screen Sharing Server | 9.8 Critical | Confirmed under active exploitation before the patch shipped |
| CVE-2026-65414 | Bluetooth | 9.8 Critical | Remote, network-vector code execution affecting all eight patched platforms |
| CVE-2026-65346 | ImageIO | 8.8 High | Arbitrary code execution simply from processing a malicious image file |
What ties these three together is that none of them require the kind of user mistake that most security advice focuses on — no phishing link, no malicious app install, no permission prompt approved carelessly. A Bluetooth-based remote code execution bug, in particular, can potentially be triggered by proximity alone on a vulnerable, unpatched device, which is about as close to a worst-case scenario as a mobile vulnerability gets.
Why the Screen Sharing bug is the one to take most seriously
A critical severity score is one thing; confirmed active exploitation is another. CVE-2026-65400 wasn't a theoretical finding from a lab — it was already being used against real devices when Apple shipped the fix. That's the single strongest signal in any security bulletin that you should stop deferring the update.
Why So Many Fixes Land at Once
273 CVEs in one release sounds alarming, but it's largely a function of timing rather than a sudden collapse in software quality. Apple's major annual OS release bundles a year's worth of internal audits, third-party research, and bug bounty submissions into a single coordinated disclosure, rather than trickling fixes out individually and giving attackers a roadmap to which older versions are still vulnerable to what. A large number in September is a sign the disclosure process worked as intended — not that iOS 27 launched broken.
If Your Device Can't Run iOS 27
Not every iPhone or iPad that's still supported can run the newest major version. That's what the parallel iOS/iPadOS 26.7 release is for — it backports the same critical security fixes, including the Bluetooth and Screen Sharing issues, to devices on the previous major version without requiring the full upgrade. If Settings shows 26.7 as your available update instead of 27, that's still the security-relevant update to install; you're not missing the protection, just the new features.
What to Do Right Now
- Update immediately — Settings > General > Software Update, on every iPhone, iPad, and Mac you own, not just your primary device
- Turn on automatic updates — Settings > General > Software Update > Automatic Updates, so the next critical patch doesn't sit unapplied for weeks
- Restart after installing — some of these fixes only take effect after a reboot
- Don't skip watchOS and tvOS — smaller, easy-to-forget devices got the same critical fixes and are just as reachable over Bluetooth
Where a VPN Does and Doesn't Help
It's worth being direct about this: a VPN does not patch a Bluetooth vulnerability or an image-parsing bug. Those are flaws in the device's own code, and the only real fix is Apple's update. What a VPN does do is reduce the exposure of the other half of your attack surface — unencrypted network traffic on public Wi-Fi — while you're in the gap between a vulnerability being disclosed and every device you own actually getting patched. See our breakdown of how a VPN protects you from hackers for where that boundary actually sits, and what can and can't be compromised on a VPN itself.
Update Your Device, Encrypt Your Connection
Patching closes the vulnerability. CarrotVPN encrypts the network in the meantime, free, with no account required on Android.
Download CarrotVPN Free