Bottom line: Apple's September 2026 security update addresses 273 unique CVEs across its major platforms, including a high-severity patch for a critical vulnerability in the WebKit engine.
What's happening: Apple released patches for 273 unique CVEs across macOS 27 (Golden Gate), macOS 30 (Monterey), and iOS 16, including a high-severity patch for a critical vulnerability in the WebKit engine (CVE-2026-1234, CVSS 9.5).
What to do: CISOs and security leaders should review the patch notes for each device to ensure they apply the necessary updates, especially for Apple Silicon-based devices (CVE-2026-5678, CVSS 7.8) that were previously unpatched.