Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino's history.
While this CVE count is notable compared to some vendors - hello, Microsoft’s record 974 bugs disclosed earlier this month - it does set a company record for Apple.
The silver lining for everyone updating their Apple products right now: none of the vulnerabilities are listed as being under active exploitation.
Apple’s latest mobile and operating system versions, iOS 27 and macOS 27 Golden Gate, released on Monday, also address a record 122 and 204 security vulnerabilities, respectively, across phone, iPad, and computer operating systems.
Just two of the iPhone and iPad CVEs fixed with iOS 27 credit a coding agent or AI assistant with finding them. Apple credited AI-bug-finding firm Calif, along with Claude and Anthropic Research, with finding and reporting this security flaw.
Then there's CVE-2026-65409, a type-confusion issue in iOS’ Foundation framework that can be abused to cause a denial of service, also found by Calif - specifically human researcher Bruce Dang - in collaboration with Claude and Anthropic Research.
Apple credited Nosebeard Labs’ Andreas Jaegersberger and Ro Achterberg with reporting this bug.
The new macOS 27 update that addresses 204 vulns also fixes both the AI hunted bugs: CVE-2026-65410 and CVE-2026-65409.
Grattafiori, the Nvidia AI Red Team, Meridian Miftari, and Amy from amys.website said this flaw to Apple.
CVE-2026-43719 is another SMB use-after-free bug, discovered by Calif’s Dang and Jakob Pammer, Claude, and Anthropic.