Apple overhauls security with iOS and macOS 27

Key points

iOS 27 fixes 122 vulnerabilities and macOS 27 fixes over 200, with some credited to AI systems such as Claude and Codex Security.

Apple overhauls security with iOS and macOS 27

Apple overhauls security with iOS and macOS 27

Key points

  • iOS 27 fixes 122 vulnerabilities and macOS 27 fixes over 200, with some credited to AI systems such as Claude and Codex Security.
  • Apple has strengthened enterprise authentication, added new executable code controls on Macs and retired legacy update management in favour of declarative management.
  • An ambitious AI agent from the betas that would detect compromised passwords and automatically change them has been put on hold.




Apple overhauls security with iOS and macOS 27










Apple’s updated operating systems have come out of beta testing, bringing in a substantial number of new security features and bug fixes.

Timed to coincide with the release of its new iPhone range, Apple’s iOS 27 mobile operating system security update addresses 122 vulnerabilities.

Its closely related desktop counterpart, macOS, fixes over 200 vulnerabilities in version 27 with some security updates backported to earlier supported releases of the OS.

Fixes included handling memory corruption bugs, privilege escalation, kernel memory access and remote code execution, with some of the bugs being credited to artificial intelligence systems such as Anthropic’s Claude and OpenAI’s Codex Security.

On top of the patches, Apple has also strengthened enterprise authentication, introduced new controls over executable code on Macs, tightened the security of managed devices and added new security boundaries around Apple Intelligence.

In macOS 27, organisations using Platform Single Sign-On (SSO) can mandate using Touch ID for biometric authentication along with a password, on supervised Macs.

An Apple Watch can also be used for the same purpose.

Platform SSO is also being extended with web-based authentication, QR codes and other modern identity provider workflows.

Apple has retired legacy update management in all 27.0 operating systems.

This covers software update commands, queries, recommended cadence settings, and deferral restrictions, leaving declarative management as the only supported way to manage and enforce updates from now on.

Fine-grained application execution controls

Apple is giving organisations substantially more control over what software is allowed to execute on their Macs.

A new set of declarative management controls can be used to allow or deny executable binaries, with rules based on code-signing properties.

Apple’s Endpoint Security framework can terminate processes associated with a binary that has been denied.

In that scenario, administrators can also automatically allow managed applications without having to maintain an individual rule for every application.

AI security headaches 

Artificial intelligence has brought in new and unconventional security concerns that Apple is seeking to address in the new operating system versions.

For example, a fix is bundled in macOS 27 for a bug that involved Apple Intelligence allowing an application to bypass security prompts; this was handled with improved state management.

As announced at WWDC2025, Apple’s Foundation Models framework makes on-device models available to developers, while more demanding workloads can use Apple’s Private Cloud Compute infrastructure which for 2026 includes a server large language model (LLM).

That architecture is designed to keep sensitive processing private while allowing larger models to operate beyond the capabilities of the device.

Apple Intelligence can be restricted to specific external integration workspace IDs that require sign-in to use.

Device management can restrict the use of Siri AI, Visual Intelligence and Natural Language Calendar Editing as well.

One AI-powered security feature from the iOS/macOS 27 betas that has been put n hold is the ambitious agent that would allow Apple Intelligence to detect compromised passwords, and help automatically change them.

Why Apple decided to delay the feature has not been spelled out, but an AI agent that can navigate a website, authenticate, change credentials and update a password manager would also possess extraordinarily sensitive privileges.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.