ANSSI flags mass Apple patch across all platforms
ANSSI advisory catalogs 200+ vulnerabilities across iOS, macOS, Safari, watchOS, tvOS, visionOS and Xcode, several enabling remote code execution and privilege escalation.
The French national cybersecurity agency (ANSSI) has issued a bulletin consolidating Apple's security updates released in August and September 2026, covering essentially the entire Apple software ecosystem: iOS/iPadOS (up to 26.7/27), macOS Golden Gate, Sequoia (15.8) and Tahoe (26.7), Safari 27, tvOS 27, visionOS (26.6.1/27), watchOS 27, and Xcode 27. The advisory aggregates over 200 distinct CVEs affecting these products, with vulnerability classes spanning remote code execution, privilege escalation, data integrity and confidentiality violations, security-policy bypass, remote denial of service, and indirect code injection (cross-site scripting) in WebKit/Safari components.
No evidence of in-the-wild exploitation is cited in this bulletin, and no proof-of-concept or technical exploitation details are provided — this is a standard vendor-patch rollup rather than an active-campaign report. Given the breadth of affected components (kernel, WebKit, system frameworks) and the presence of remote code execution and privilege escalation issues across essentially all current Apple platforms, defenders managing Apple fleets (iOS/macOS/enterprise Mac and mobile device management) should prioritize deployment of the referenced updates. ANSSI's guidance is simply to apply the vendor patches referenced in Apple's security bulletins (148353, 149034–149043).
Because this is a broad, multi-CVE rollup rather than a single deep-dive vulnerability report, defenders should treat this as routine patch management: confirm MDM/patch compliance for all listed OS/app versions, prioritize internet-facing or browser-exposed endpoints (Safari/WebKit CVEs) and any devices handling untrusted content, and monitor vendor advisories for any later addition of in-the-wild exploitation notes.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1172
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free