Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

iOS 27 Security and Privacy Settings Guide

A comprehensive guide to configuring security and privacy settings on iOS 27 (released September 14, 2026) and on the iOS 26.7 security-only track, to protect your personal data and secure your iPhone.


Which Version Should You Be On?

On September 14, 2026 Apple released two updates at once, and both are offered in Software Update. This is unusual and worth understanding before you tap anything.

TrackCurrent versionWhat you getWho it is for
iOS 2727.0All new features, plus the same security fixesMost people
iOS 26.726.7Security fixes only, no new featuresAnyone who wants to wait before moving to a new major version

On a device running iOS 26, iOS 26.7 currently appears as the default update, with iOS 27 listed as an option lower down the Software Update screen. Apple is expected to make iOS 27 the primary offer within a few weeks, but has not announced a date.

Both are secure right now. iOS 26.7 and iOS 27 share roughly 75 of the same CVE fixes. Staying on 26.7 is a legitimate choice, not a compromise — for the moment.

Important

Apple has made no public commitment to how long the iOS 26.x security track will be maintained. Historically Apple has shipped security-only updates for the previous major version for roughly a year, but that is precedent, not a promise. If you stay on 26.7, treat it as a temporary position and plan to move to iOS 27 rather than settling there indefinitely.

One genuine reason to stay: iPadOS 27 drops several older iPads that iPadOS 26.7 still supports. On iPhone the device list is identical — iPhone 11 and later for both — so iPhone users are not being forced to choose between security and their hardware.


What’s New in iOS 26 and iOS 27

iOS 26 (released September 15, 2025) represents Apple’s biggest security and privacy update in years. Apple jumped from iOS 18 to iOS 26 to align version numbers with the year across all operating systems.

Major Security & Privacy Additions in iOS 26

  • Wi-Fi Aware – Secure peer-to-peer connections without internet access points
  • Post-Quantum Cryptography – Hybrid key exchange protecting against future quantum computing threats
  • Expanded Passkey Support – Automatic passkey creation and migration from passwords
  • Advanced Tracking Protection for All Browsing – Anti-fingerprinting expanded beyond Private Browsing
  • Wired Accessories Security – Explicit permission controls for USB-C/Lightning accessories
  • Enhanced Parental Controls – Stronger child account management and content filtering
  • Password Version History – Track changes to saved passwords over time
  • Secure Password Export – FIDO Alliance standard for moving credentials between managers
  • Liquid Glass Design – New translucent interface (including privacy-focused opacity controls)

Release Timeline at a Glance

VersionReleasedSecurity content
iOS 26Sep 15, 2025Initial release
iOS 26.1Nov 3, 2025Routine patches
iOS 26.2Dec 12, 202526+ fixes, two exploited WebKit zero-days
iOS 26.2.1Jan 26, 2026No published CVEs (AirTag 2 support)
iOS 26.3Feb 11, 202637 fixes, exploited dyld zero-day (CVE-2026-20700)
iOS 26.3.1Mar 4, 2026No published CVEs
iOS 26.4Mar 24, 202637 fixes; Stolen Device Protection on by default
iOS 26.4.1Apr 8, 2026No published CVEs
iOS 26.4.2Apr 22, 20261 fix – deleted notifications retained (CVE-2026-28950)
iOS 26.5May 11, 202650+ fixes; encrypted RCS begins rolling out
iOS 26.5.1Jun 1, 2026No published CVEs (iPhone 17/Air only)
iOS 26.5.2Jun 29, 2026~37 fixes, mostly WebKit
iOS 26.6Jul 27, 202678 entries / 87 unique CVEs
iOS 26.6.1Aug 17, 2026~29 fixes, mostly WebKit
iOS 26.6.2Sep 8, 2026No published CVEs (cellular update fix)
iOS 26.7Sep 14, 202680+ fixes, security-only track
iOS 27Sep 14, 2026100+ fixes; new major version
Note

Only one actively exploited iOS zero-day has been disclosed in 2026 so far: CVE-2026-20700 in dyld, patched in iOS 26.3 on February 11, 2026. Every release from iOS 26.4 onwards, including iOS 26.7 and iOS 27, has shipped without a known in-the-wild exploit. That is not a reason to delay updating — Apple’s advisories are a public roadmap for attackers targeting people who have not yet installed them.

iOS 26.2 Security Updates (December 2025)

  • 26+ security vulnerabilities patched, including two actively exploited WebKit zero-days
  • AirDrop security codes – One-time codes for sharing with unknown contacts
  • Hidden Photos fix – Addressed vulnerability allowing unauthorized access
  • FaceTime caller ID spoofing – Patched to prevent impersonation attacks
  • iMessage privacy controls – Improved data handling

iOS 26.2.1 (January 26, 2026)

iOS 26.2.1 is a minor update focused on new hardware support and bug fixes.

New Features:

  • AirTag (2nd Generation) support – Required for the new AirTag with:
    • Second-generation Ultra Wideband (UWB) chip for 50% longer Precision Finding range
    • Precision Finding on Apple Watch (Series 9+, Ultra 2+) for the first time
    • 50% louder speaker for easier locating and enhanced anti-stalking measures
    • Expanded Bluetooth range for better Find My network detection
    • Share Item Location with 36+ airlines for lost luggage recovery

Bug Fixes:

  • Emergency calling fix for older mobile phones
  • Unspecified stability improvements

Security Notes:

  • No published CVE entries for iOS 26.2.1 itself
  • Users on iOS 26-compatible devices should update to maintain security (older iOS versions only receive certificate updates)

Also Released:

  • iOS 18.7.4, iOS 16.7.13, iOS 15.8.6, iOS 12.5.8 – Certificate updates for iMessage, FaceTime, and Apple account sign-in (valid until January 2027)
Critical

iOS 26.2.1 is required for AirTag (2nd Generation). Update via Settings > General > Software Update.

iOS 26.3 (February 11, 2026)

iOS 26.3 addresses 37 security vulnerabilities including one actively exploited zero-day, adds new privacy controls, and introduces a data transfer tool for users switching to Android.

Security Fixes:

  • Actively exploited zero-day (CVE-2026-20700) – A memory corruption flaw in the dyld dynamic link editor that allowed arbitrary code execution. Apple says it “may have been exploited in an extremely sophisticated attack against specific targeted individuals” on versions before iOS 26. Reported by Google Threat Intelligence Group; the first Apple flaw added to CISA’s Known Exploited Vulnerabilities catalog in 2026.
  • 3 kernel/privilege escalation flaws – Including CVE-2026-20617 and CVE-2026-20615 (CoreServices race condition and path handling bugs allowing root privileges) and CVE-2026-20626 (kernel root privilege escalation)
  • Sandbox escape (CVE-2026-20667) – A logic flaw in libxpc allowing apps to break out of the sandbox
  • Remote file write (CVE-2026-20660) – A CFNetwork path handling vulnerability allowing remote attackers to write arbitrary files
  • Lock screen photo access (CVE-2026-20642) – A bug in Photos allowing someone with physical access to view photos from the lock screen
  • Accessibility data leaks (CVE-2026-20674) – Sensitive user information viewable on a locked device
  • Additional fixes in WebKit, ImageIO, CoreAudio, Game Center, Messages, Shortcuts, and StoreKit
Critical

The dyld zero-day (CVE-2026-20700) was actively exploited in targeted attacks. Update to iOS 26.3 or later immediately via Settings > General > Software Update.

New Features:

  • Limit Precise Location – Reduces what cellular carriers can infer about your location to neighborhood-level instead of street-level precision. Requires iPhone 16e or iPhone Air (C1/C1X modem). Currently supported by Boost Mobile (US), EE/BT (UK), Telekom (Germany), and AIS/True (Thailand).
  • Transfer to Android – A new proximity-based tool for migrating photos, messages, notes, apps, passwords, and phone number to an Android device. Health data and locked notes remain on iPhone.
  • Encrypted RCS messaging support – System-level support for encrypted Rich Communication Services messaging is now present in the OS code, pending carrier activation.

EU-Only Features (Digital Markets Act compliance):

  • Notification forwarding – Forward iPhone notifications to third-party wearables (not just Apple Watch)
  • Proximity pairing – One-tap pairing for third-party headphones and smartwatches, similar to AirPods

iOS 26.3.1 (March 4, 2026)

iOS 26.3.1 is a minor maintenance update released alongside Apple’s March 2026 product announcements. It focuses on new hardware support, performance improvements, and bug fixes.

New Hardware Support:

  • iPhone 17e – Full support for the newly announced iPhone 17e
  • Studio Display (2026) – Compatibility with the new Studio Display
  • Studio Display XDR – Compatibility with the new Studio Display XDR

Improvements:

  • Improved app responsiveness and smoother multitasking
  • Minor storage optimization compared to iOS 26.3
  • Unspecified bug fixes and stability improvements

Security Notes:

  • No published CVE entries for iOS 26.3.1 itself
  • Users on older iOS versions can update to iOS 18.7.6 for legacy security patches
Note

iOS 26.3.1 was released without a beta testing phase, alongside the iPhone 17e and new Studio Display announcements. While it contains no new CVEs, it builds on the 37 security fixes in iOS 26.3 — users should update to stay current.

iOS 26.4 (March 24, 2026)

iOS 26.4 addresses 37 security vulnerabilities across the kernel, WebKit, baseband, and application frameworks. It also changes a key default for Stolen Device Protection.

Security Fixes:

  • Stolen Device Protection bypass (CVE-2026-28895) – Someone with physical access could bypass biometric-only protections using just the passcode, undermining the core purpose of the feature
  • Keychain access flaw (CVE-2026-28864) – Insufficient permission checks allowed unauthorized access to Keychain items
  • Network traffic interception (CVE-2026-28865) – An attacker in a privileged network position could intercept traffic; discovered by researchers at KU Leuven
  • Kernel privilege escalation (CVE-2026-20698, CVE-2026-20687) – Apps could cause unexpected system shutdowns or corrupt kernel memory, opening a path to privilege escalation
  • Kernel state leak (CVE-2026-28868) – An app could leak sensitive kernel state information
  • WebKit Same Origin Policy bypass (CVE-2026-20643) – Allowed cross-origin data access in Safari
  • Content Security Policy bypass (CVE-2026-20665) – Weakened CSP enforcement in WebKit
  • WebKit sandbox escape (CVE-2026-28859) – A malicious website could process restricted web content outside the sandbox
  • Cross-site scripting (CVE-2026-2887) – XSS vulnerability via visiting a malicious website
  • Sandbox escape via AirPrint (CVE-2026-20688) – A path handling issue in the Printing framework allowed an app to break out of its sandbox
  • Baseband vulnerabilities (CVE-2026-28874, CVE-2026-28875) – Remote attacker could cause app termination; buffer overflow addressed with improved bounds checking
  • Media processing out-of-bounds access (CVE-2026-20690) – Processing a maliciously crafted media file could terminate the process
  • Sensitive user data access (CVE-2026-28877) – An app could access sensitive user data without proper authorization
  • App enumeration privacy issue (CVE-2026-28886) – An app could enumerate which other apps were installed on the device
  • Mail Privacy bug (CVE-2026-20692) – “Hide IP Address” and “Block All Remote Content” settings in Apple Mail were not functioning correctly, potentially leaking user IP addresses and loading remote tracking content
Critical

CVE-2026-28895 allowed Stolen Device Protection to be bypassed with just a passcode — the exact scenario the feature is designed to prevent. The Mail Privacy bug (CVE-2026-20692) also meant “Hide IP Address” and “Block All Remote Content” were silently failing. Update to iOS 26.4 or later immediately via Settings > General > Software Update.

Threat Context:

iOS 26.4 was released amid active exploitation of two sophisticated attack chains:

  • DarkSword exploit chain – A full-chain iOS exploit going from a website visit to full device compromise (WebKit → Safari → dyld → kernel), attributed to commercial spyware vendors and state-sponsored actors. Active since at least November 2025. Apple expanded DarkSword patches to iOS 18.7.7 for users on older devices.
  • Coruna exploit chain – Another multi-stage exploit chain that prompted rapid security responses from Apple in preceding months

New Default Behavior:

  • Stolen Device Protection enabled by default – As of iOS 26.4, Stolen Device Protection is enabled by default on consumer devices. Previously, users had to opt in manually.

iOS 26.4.1 (April 8, 2026)

iOS 26.4.1 completes the Stolen Device Protection rollout and fixes a significant iCloud syncing issue.

Changes:

  • Stolen Device Protection enabled by default for enterprise/MDM-managed devices – Completing a two-stage rollout that began with consumer devices in iOS 26.4. Enterprise administrators can still configure the feature via MDM profiles.
  • iCloud password syncing fix – Resolved a CloudKit bug introduced in iOS 26.4 that broke password syncing via the Passwords app. Users who noticed missing or stale passwords across devices should update immediately.

Security Notes:

  • No new CVE entries for iOS 26.4.1 itself
  • Builds on all 37 security fixes from iOS 26.4
  • Users on older iOS versions can update to iOS 18.7.7 for DarkSword exploit chain patches
Important

If your Passwords app was not syncing credentials across devices, the CloudKit bug in iOS 26.4 is the cause. Update to iOS 26.4.1 and verify that all passwords appear correctly on all devices.

iOS 26.4.2 (April 22, 2026)

iOS 26.4.2 patches a single vulnerability, but it is one of the most consequential privacy fixes of the year.

Security Fix:

  • Deleted notifications retained (CVE-2026-28950) – A logging issue in Notification Services meant that notifications marked for deletion could be unexpectedly retained on the device. Apple addressed it with improved data redaction.

Why this matters:

This is the flaw that allowed forensic extraction of Signal message previews from an iPhone whose owner had deleted the Signal app and had disappearing messages configured. The Lock Screen preview text survived in the on-device notification database and was recoverable by anyone with physical extraction capability. Apple did not mark the flaw as actively exploited, but it was demonstrably used in the field.

Critical

If your threat model includes device seizure or physical forensic extraction, iOS 26.4.2 is the minimum version you should run. Notification previews are a persistent leak channel: even on a patched device, consider setting Settings > Notifications > Show Previews to Never, or turning off previews for your messaging apps individually.

Also released: iOS 18.7.8 for older devices, with the same fix.

Related advisory: On April 14, 2026, Apple published a separate warning that researchers had identified web-based attacks against out-of-date iOS 13, 14, 15 and 16 devices via malicious web content. Apple stated that devices with Lockdown Mode enabled are protected from these specific attacks even on out-of-date software — a rare public confirmation of the mode’s real-world value.

iOS 26.5 (May 11, 2026)

iOS 26.5 addresses more than 50 security vulnerabilities and activates end-to-end encrypted RCS messaging. It was released alongside iPadOS 26.5, macOS 26.5, watchOS 26.5, tvOS 26.5, and visionOS 26.5.

Security Fixes:

  • Kernel privilege escalation (CVE-2026-28951) – An authorization flaw in state management allowed an app to gain root privileges. Reported by Csaba Fitzl.
  • Kernel memory corruption (CVE-2026-28972) – An out-of-bounds write allowed an app to cause unexpected system termination or write kernel memory.
  • Sandbox escape via App Intents (CVE-2026-28995) – A logic issue allowed a malicious app to break out of its sandbox. Reported by Vamshi Paili and Tony Gorez.
  • Remote kernel memory corruption (CVE-2026-43668) – A use-after-free in mDNSResponder allowed a network attacker to corrupt kernel memory.
  • WebKit use-after-free (CVE-2026-28942) – A memory management bug caused Safari to crash on malicious content. Reported by Milad Nasr and Nicholas Carlini at Anthropic, with assistance from Claude.
  • WebKit Content Security Policy bypasses (CVE-2026-43660, CVE-2026-28907) – Allowed CSP enforcement to be weakened.
  • WebKit information disclosure (CVE-2026-28962) – Sensitive data could leak from maliciously crafted web content.
  • WebKit sandbox/data access (CVE-2026-28958) – Web content could access sensitive user data; additional WebKit crashes patched (CVE-2026-43658, CVE-2026-28905, CVE-2026-28847, CVE-2026-28883).
  • CoreAnimation data exposure (CVE-2026-28964) – A UI inconsistency allowed an app to access sensitive user data.
  • Storage race condition (CVE-2026-28996) – Enabled unauthorized data access.
  • Screenshot leak via Visual Intelligence (CVE-2026-28963) – A physical attacker could access sensitive data through Visual Intelligence during iPhone Mirroring on iPhone 15 and later.
  • Wi-Fi denial of service (CVE-2026-28994) – A network-adjacent attacker could cause DoS via crafted Wi-Fi packets.

No actively exploited zero-day was disclosed in this release.

Important

iOS 26.5 patches over 50 vulnerabilities including a kernel root privilege escalation, a sandbox escape, and a remote kernel memory corruption via mDNSResponder. Apple also released iOS 18.7.9, 16.7.16, and 15.8.8 for older devices.

New Features:

  • End-to-end encrypted RCS messaging (beta) – Messages now supports E2EE for RCS conversations between iPhone and Android users. Both participants need a carrier that supports the GSMA’s RCS Universal Profile with encryption, and the Android side needs a current version of Google Messages; rollout is gradual. Encryption is automatic — there is no toggle. Encrypted RCS messages display a small lock icon, matching iMessage.
  • Pride Luminance wallpaper – A new dynamic wallpaper that refracts a spectrum of colors, matching the Pride Luminance Apple Watch face and band.
  • Suggested Places in Maps – Recommendations based on trending nearby locations and your recent searches. Apple has noted that groundwork for Maps ads (launching summer 2026) is included in this update.
Note

Encrypted RCS is in beta and only activates when both participants’ carriers and apps support it. Encryption is per-conversation, and the lock icon is the only indicator — if you do not see the lock, treat that chat as unencrypted in transit even on iOS 26.6.1.

iOS 26.5.1 (June 1, 2026)

A narrow hardware fix released only for iPhone 17 (all models) and iPhone Air.

  • No published CVE entries. This update carries no security content.
  • Fixes an issue that could prevent wired charging on iPhone Air and iPhone 17 models when the battery is nearly drained.

If you own any other iPhone, this update does not apply to you — stay on iOS 26.5 until 26.5.2.

iOS 26.5.2 (June 29, 2026)

iOS 26.5.2 patches roughly 37 vulnerabilities, overwhelmingly in WebKit. None are known to have been actively exploited.

Kernel:

  • CVE-2026-43724 – An app could cause unexpected system termination or write kernel memory
  • CVE-2026-43722 – An app could leak sensitive kernel state
  • CVE-2026-39868 – An app could corrupt kernel memory

Sandbox escape (most serious class in this release):

  • CVE-2026-43725, CVE-2026-43701 – A malicious website could process restricted web content outside the WebKit sandbox

Privacy and data exfiltration:

  • CVE-2026-43721 – WebKit Storage: clipboard data hijacking
  • CVE-2026-43735, CVE-2026-43708 – Cross-origin data exfiltration
  • CVE-2026-43700, CVE-2026-43732, CVE-2026-43713 – Sensitive user information disclosure
  • CVE-2026-43740 – Process memory disclosure

Other components: IOGPUFamily (CVE-2026-43743), MobileAccessoryUpdater (CVE-2026-43807, exploitable by a malicious accessory), Web Extensions (CVE-2026-43704), libxslt (CVE-2026-43706, CVE-2026-43703), WebRTC (CVE-2026-28979, CVE-2026-43718, CVE-2026-43717, CVE-2026-43746).

Note

Four WebKit bugs in this release were found by AI security tooling: CVE-2026-43707, CVE-2026-43716 and CVE-2026-43745 by OpenAI Codex Security, and the use-after-free CVE-2026-43715 by Milad Nasr and Nicholas Carlini at Anthropic. This is the first Apple advisory where AI-discovered vulnerabilities make up a visible share of the fixes.

iOS 26.6 (July 27, 2026)

The largest security release of the iOS 26 cycle: 78 vulnerability entries covering 87 unique CVEs. None are known to have been actively exploited. (The widely quoted “150+” figure refers to macOS Tahoe 26.6, not iOS.)

Most serious fixes:

  • Root privilege escalation (CVE-2026-43723) – A path handling issue in MediaRemote allowed an app to gain root privileges
  • Kernel code execution (CVE-2026-64747) – AVEVideoEncoder: an app could execute arbitrary code with kernel privileges
  • Code-signing bypass (CVE-2026-43813) – CloudAttestation failed to enforce code signing correctly
  • Sandbox escapes – Game Center (CVE-2026-64740), libc (CVE-2026-28973), MediaRemote (CVE-2026-43723)
  • Arbitrary code execution from an image (CVE-2026-43818) – ImageIO
  • Arbitrary code execution from crafted files – SceneKit (CVE-2026-64763, CVE-2026-64764, CVE-2026-64765, CVE-2026-64766)
  • ~20 kernel entries, including CVE-2026-64735 (remote network filter bypass), CVE-2026-28931 (a malicious NFS server could corrupt kernel memory) and CVE-2026-43810 (remote kernel memory corruption)

Privacy-relevant fixes:

  • CVE-2026-64732 – Accessibility: physical access could expose sensitive data during iPhone Mirroring
  • CVE-2026-43753 – DriverKit: physical access to a locked device could reveal sensitive information
  • CVE-2026-64741 – Sandbox Profiles: an app could read a persistent device identifier
  • CVE-2026-64746, CVE-2026-43797, CVE-2026-64734 – Contacts: adding contacts without authorization and related data access
  • CVE-2026-64733 (Accounts Framework), CVE-2026-43730 (AuthKit) – Fingerprinting vectors
  • CVE-2026-64726 – Wi-Fi: a proximate attacker could corrupt process memory

User-facing changes:

  • Spotlight index optimization – Reindexing work is moved off the iOS 27 upgrade itself, so the first week on iOS 27 will not be dominated by background indexing
  • Blocked Contacts Limit Reached alert – iOS now tells you when your block list is full and you must remove an entry before adding another. Worth knowing if you are managing harassment: the block list has a hard cap.
  • Enterprise Wi-Fi privacy fix – The DisableAssociationMACRandomization MDM setting was not actually preventing users from changing their Private Wi-Fi Address; it now works as documented
Important

The anti-snatching feature has NOT shipped. Code discovered in May 2026 describes a feature that uses the gyroscope, accelerometer and a paired Apple Watch to detect an iPhone being grabbed out of your hand, then instantly locks the device and activates Stolen Device Protection. That code is present but dormant in iOS 26.6 — there is no toggle and no Settings path. Several outlets reported it as shipping in 26.6; they were wrong. It did not ship in iOS 27 either: it is absent from Apple’s iOS 27 feature material and from the launch coverage, and Apple has never announced it. Apple has also not said it was cut. Treat it as unreleased and do not rely on it.

iOS 26.6.1 (August 17, 2026)

A focused WebKit hardening release: about 29 CVEs, with 19 in WebKit alone. None are known to have been actively exploited.

Most notable:

  • IPSec authentication bypass (CVE-2026-65329) – Telephony: an attacker in a privileged network position could bypass IPSec authentication and intercept network traffic. This is the fix that matters most for anyone relying on IPSec-based VPNs on cellular.
  • Arbitrary code execution from an image (CVE-2026-65346) – ImageIO integer overflow
  • Kernel (CVE-2026-65343, CVE-2026-65349, CVE-2026-65330) – Use-after-free allowing remote system termination; reading kernel memory; corrupting kernel memory
  • WebKit memory corruption (CVE-2026-65341, CVE-2026-43794)
  • WebKit History data leak (CVE-2026-64778) – Visiting a malicious website could leak sensitive data
  • WebKit Storage (CVE-2026-64779)
  • IOGPUFamily (CVE-2026-64788) – Web content could corrupt memory
  • Audio (CVE-2026-65339) – Sensitive information leak

macOS Tahoe 26.6.2 shipped alongside with the same WebKit fixes.

Critical

iOS 26.6.1 was superseded on September 14, 2026. Move to iOS 26.7 or iOS 27 via Settings > General > Software Update, and turn on Automatic Updates so you are not depending on remembering.

iOS 26.6.2 (September 8, 2026)

A single-purpose maintenance release with no published CVE entries. Apple’s entire release note reads: “This update fixes an issue that prevents downloading a software update over a cellular connection.”

Available for iPhone 11 and later, and the same iPad models as iOS 26.6.1.

Important

This update contains no security patches, but it matters for security anyway — which is a distinction worth being precise about. The bug it fixes prevented affected devices from downloading updates over cellular at all. Six days later Apple shipped over a hundred CVE fixes in iOS 26.7 and iOS 27. A phone that only ever reaches the internet over mobile data would have been stuck on iOS 26.6.1, unable to pull them.

The vulnerability was never in the cellular bug itself — it was in not being able to receive the next patch. If a device you look after cannot see updates in Software Update, connect it to Wi-Fi or a computer, install 26.6.2, and then update normally.

iOS 26.7 (September 14, 2026)

The first release on the iOS 26 security-only track. Apple’s release note describes it simply as security fixes for your iPhone; there are no new features.

  • Over 80 security fixes, roughly 75 of them shared with iOS 27
  • Kernel memory corruption and privilege escalation, including CVE-2026-28968 and CVE-2026-43689
  • Sandbox escape to kernel (CVE-2026-84607) – AVEVideoEncoder: a sandboxed app could execute arbitrary code with kernel privileges
  • WebKit use-after-free (CVE-2026-43715, CVE-2026-64718)
  • Further fixes in ImageIO, IOGPUFamily and CoreMedia, plus privacy and entitlement fixes across Accessibility, BackgroundAssets, Music, Photos, Safe Browsing, Spotlight and XPC
  • No actively exploited vulnerabilities

Available for the full iOS 26 device list: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

iOS 27 (September 14, 2026)

iOS 27 shipped on September 14, 2026, announced at WWDC on June 8. Device support on iPhone is unchanged from iOS 26 — iPhone 11 and later. On iPad, iPadOS 27 requires iPad Pro 12.9-inch 4th generation or later, iPad Pro 11-inch 2nd generation or later, iPad Air 4th generation or later, iPad 9th generation or later, or iPad mini 6th generation or later, dropping several models that iPadOS 26.7 still supports.

Security content: over 100 vulnerabilities fixed across roughly 75 components, including Kernel, WebKit, Sandbox, TCC, Baseband, Bluetooth, Telephony, Siri, Spotlight, SpringBoard and Software Update. None are known to have been actively exploited.

Notable fixes include kernel out-of-bounds writes, use-after-frees and race conditions (CVE-2026-28968, CVE-2026-28969, CVE-2026-84561, CVE-2026-84566, CVE-2026-84507, CVE-2026-84602, CVE-2026-84622, CVE-2026-43689, CVE-2026-65405, CVE-2026-65415), WebKit remote code execution and a webarchive universal cross-site scripting flaw (CVE-2026-84635, CVE-2026-64753, CVE-2026-86898, CVE-2026-64718), the AVEVideoEncoder sandbox-to-kernel escape (CVE-2026-84607), Keychain credential theft, unauthorised Bluetooth access, and a Bluetooth remote code execution flaw.

Note

Published CVE counts for iOS 27 vary between outlets from “over 100” to well over 200, because Apple’s advisory lists some CVEs under several components and different counters treat that differently. “Over 100” is the safe figure. The precise number matters less than the fact that both September 14 releases are large.

AI-assisted vulnerability research continues to show up in Apple’s credits. On the iOS 27 page, CVE-2026-65410 (AVEVideoEncoder) and CVE-2026-65409 (Foundation) are credited to Calif.io in collaboration with Claude and Anthropic Research. The iOS 26.7 page carries those two plus the WebKit use-after-free CVE-2026-43715, credited to Milad Nasr and Nicholas Carlini with Claude at Anthropic — continuing the pattern that began with iOS 26.5 and 26.5.2.

Trust Insights — real-time scam detection

The headline security framework, and it shipped. Apps can ask the system, at a sensitive moment, whether the user appears to be in the middle of being socially engineered — the “scam coaching” pattern where a fraudster talks someone through a payment, a password reset or a document signature in real time.

  • Apps request an evaluation and receive a risk level (medium or high), then decide whether to warn, delay, or add verification
  • Covers five operation categories: payments and in-app purchases, account credential or security changes, resource-intensive requests, message sending and document signing, and other
  • Privacy model: analysis of interaction patterns, timing, context and basic sensor data happens on device. Apple states it does not inspect the contents of Photos, Messages or Mail, that the underlying signals are discarded immediately, and that only a single risk value leaves the device

How you will actually encounter it: Trust Insights works on two levels. An app must hold a specific Apple entitlement (com.apple.developer.trustinsights.base) and request your authorisation, so you will see a per-app permission prompt the first time a banking or payments app uses it — much like a camera or location prompt. Separately, Apple states that you have full control and can disable Trust Insights in Settings, though it has not documented the path or the toggle’s name. In practice, expect a per-app prompt first and a system-level switch behind it.

Important

Apple’s own wording is that “a cooldown period may apply after disabling, to protect users who may have themselves been coached into turning it off.” The anti-coercion intent is real and unusual — a scammer’s first move is often to talk the victim into switching protections off — but Apple has not published how long the cooldown lasts or when it applies. Do not assume a specific delay.

Find My — Hide Location

Hide Location shipped, as a control on each person’s card inside the Find My app — not in Settings. You can hide your location from one specific person, and separately set location sharing to run for a custom duration or until a set date and time.

Important

The other person is not notified when you use Hide Location. Apple frames this around surprise parties, but the real significance is for people in coercive or controlling relationships, where “I stopped sharing my location” is itself a dangerous signal. The same silence, of course, means someone can hide their location from you without you knowing. If location sharing matters to your safety in either direction, review Settings > Privacy & Security > Safety Check rather than relying on Find My alone.

Passwords — automatic password rotation (delayed)

Important

This did not ship in iOS 27. Apple confirmed on September 11, 2026 that automatic password rotation — the Passwords app signing in to a site and replacing a weak or breached password for you — is deferred to a future software update, along with Suggestions in Messages.

Some how-to articles published around launch describe the feature as if it were live; they were written against a beta. Until it arrives, rotating a compromised password is still a manual job. The app’s warnings about weak, reused and breached credentials do work — act on them yourself.

Communication Safety — expanded scope

Now blurs gore and violence in Messages and FaceTime, in addition to nudity, for users under 18. Coverage is tied to the Child Account: mandatory under 13, available up to 18.

Apple’s own support pages currently contradict each other on whether live FaceTime video is covered as well as still content. If that distinction matters for a child in your care, verify the behaviour on the device rather than trusting either page.

Child safety and parental controls

All four announced controls shipped:

  • Ask to Browse – A child must request approval before visiting any new website in Safari; the parent reviews and approves in Messages
  • Ask to Buy for app downloads
  • Time Allowances – Daily budgets by category (Games, Entertainment, Social Media), replacing per-app limits
  • Contact approval – New numbers and accounts need parental sign-off before a child can message, call or FaceTime them

These require every device in the Family Sharing group to be on iOS 27 or the equivalent release for its platform. A child on an older device is not covered.

Apple Intelligence and Siri

Siri runs on on-device foundation models and Private Cloud Compute, with cryptographic guarantees that no data is stored or logged. Third-party model access (Claude, Gemini) arrives through a unified API.

  • Siri’s AI features are not available in the EU at launch on iOS, iPadOS and watchOS, pending work under the Digital Markets Act — and neither are features that depend on them
  • Not available in China while Apple works through regulatory requirements
  • English only at launch, with French, Japanese, Korean, Portuguese and Spanish due the following month
  • Requires iPhone 15 Pro or later
  • Apple has confirmed that Private Cloud Compute now runs partly on Google Cloud infrastructure alongside Apple’s own hardware. Apple’s position is that the cryptographic guarantees are unchanged by where the silicon sits

Sensitive Content Warning enforcement

Not an announced feature, but a real behaviour change: Sensitive Content Warning (Settings > Privacy & Security > Sensitive Content Warning) is enforced more aggressively in iOS 27. Users are reporting it greyed out or locked on where a Screen Time content restriction or an unverified age profile applies. If you cannot change it, look in Settings > Screen Time > Content & Privacy Restrictions rather than the privacy pane.

Enterprise and MDM

  • Privacy Management Declaration – Replaces PPPC with a single full-screen consent dialog instead of repeated per-permission prompts; extends to per-site camera and microphone rules in Safari
  • Credential Management – Credentials declared once and referenced by DNS Proxy, Network Relay, Always-on VPN, IKEv2, IPSec, web content filter and extensible SSO
  • Hardware integrity verification – Administrators can verify that the camera, Face ID, Touch ID, NFC and baseband have not been swapped outside authorised service
  • Apple Intelligence model controls – IT can allow or restrict on-device versus Private Cloud Compute model access by device group
Important

If your iPhone is managed by an employer, note that MDM in iOS 27 can trigger remote diagnostic log collection routed to Apple with no involvement from you, the device user. Managed devices have always been less private than personal ones; this widens the gap.


1. Device Authentication

Face ID / Touch ID Setup

Biometric authentication provides secure and convenient device access.

How to set up Face ID:

  1. Open Settings
  2. Tap Face ID & Passcode
  3. Enter your passcode
  4. Tap Set Up Face ID
  5. Follow on-screen instructions to position your face
  6. Move your head in a circle to complete the scan

Configure Face ID uses:

  • iPhone Unlock
  • iTunes & App Store purchases
  • Apple Pay
  • Password AutoFill
  • Other Apps (toggle individually)

Strong Passcode Configuration

How to set a strong passcode:

  1. Go to Settings > Face ID & Passcode
  2. Tap Change Passcode
  3. Tap Passcode Options
  4. Select Custom Alphanumeric Code (8-12 random characters recommended)

Two-Factor Authentication (2FA)

How to enable 2FA:

  1. Go to Settings > [Your Name] > Sign-In & Security
  2. Tap Turn On Two-Factor Authentication
  3. Tap Continue
  4. Enter a trusted phone number
  5. Verify with the code sent to your phone

Auto-Lock Settings

  1. Go to Settings > Display & Brightness > Auto-Lock
  2. Select a time interval (30 seconds to 5 minutes recommended)

Security Keys for Apple Account

Security keys are small external devices that look like a thumb drive or tag. They provide extra protection for your Apple Account by replacing the standard six-digit verification code with a physical device as the second factor in two-factor authentication. Because they are physical, they help prevent attackers from intercepting or requesting your second factor through phishing.

Requirements:

  • At least two FIDO® Certified security keys (e.g., YubiKey 5C NFC, YubiKey 5Ci, or FEITIAN ePass K9 NFC)
  • iOS 16.3 or later
  • Two-factor authentication already enabled on your Apple Account
  • A modern web browser

Compatible connector types:

  • NFC — Works with iPhone via tap (contactless)
  • USB-C — Works with iPhone 15 or later and most Mac models
  • Lightning — Works with iPhone 14 and earlier
  • USB-A — Works with older Mac models

How to add security keys:

  1. Go to Settings > [Your Name] > Sign-In & Security
  2. Tap Two-Factor Authentication
  3. Tap Security Keys
  4. Tap Add Security Keys
  5. Follow the on-screen instructions
  6. You can add up to six keys total

What security keys protect:

  • Signing in to your Apple Account on a new device or on the web
  • Resetting your Apple Account password or unlocking your account
  • Adding or removing security keys
Important
  • You must keep at least two security keys in safe places. If you lose all your trusted devices and security keys, you could be locked out of your account permanently.
  • Security keys are not compatible with child accounts or Managed Apple Accounts.
  • Apple Watch paired using a family member’s iPhone is not supported.
  • Devices signed in with your account that have not been used for more than 90 days will be signed out when you add security keys. You can sign back in to those devices using a security key.

2. Stolen Device Protection

Stolen Device Protection adds security when your iPhone is away from familiar locations. As of iOS 26.4, this feature is enabled by default on consumer devices, and as of iOS 26.4.1, on enterprise/MDM-managed devices as well.

Key Features

Biometric Authentication Required (no passcode fallback):

  • Accessing passwords stored in iCloud Keychain
  • Using saved payment methods in Safari
  • Turning off Lost Mode
  • Erasing all content and settings
  • Viewing Apple Card virtual card number
  • Opening locked and hidden apps

Security Delay (1-hour wait + second biometric scan):

  • Changing Apple Account password
  • Signing out of Apple Account
  • Turning off Stolen Device Protection
  • Changing Face ID or Touch ID settings
  • Changing device passcode
  • Resetting all settings
  • Turning off Find My

How to Check It Is On

  1. Go to Settings > Face ID & Passcode
  2. Enter your passcode
  3. Scroll down and tap Stolen Device Protection
  4. Confirm it is toggled on

Configuration Options

  • Away from Familiar Locations – Security features activate only when away from home/work
  • Always – Security features are always active

Requirements

  • iOS 17.3 or later (enhanced in iOS 26, enabled by default since iOS 26.4)
  • Two-factor authentication enabled
  • Face ID or Touch ID configured
  • Device passcode set
  • Find My enabled
  • Significant Locations enabled
Important

Stolen Device Protection can lock you out. Because it removes the passcode fallback, a Face ID or Touch ID failure at the wrong moment — a broken screen, an injured finger, a face that has changed — combined with the one-hour Security Delay can leave a legitimate owner unable to reach their own passwords or change their own settings. This was documented repeatedly in April 2026. Keep a recovery path that does not depend on the device: an Apple Account recovery key stored offline, and at least one trusted device or recovery contact.


3. App Privacy Controls

App Tracking Transparency

How to configure:

  1. Go to Settings > Privacy & Security > Tracking
  2. Toggle Allow Apps to Request to Track off to block all tracking
  3. Or manage individual app permissions below

App Privacy Report

View detailed app data access:

  1. Go to Settings > Privacy & Security > App Privacy Report
  2. Toggle on App Privacy Report
  3. Review 7-day history of sensor, camera, microphone, and network access

Clipboard Access Alerts

iOS 26 continues to notify you whenever apps access your clipboard, preventing silent data harvesting.

Review All Permissions

  1. Go to Settings > Privacy & Security
  2. Review each category: Location, Contacts, Photos, Microphone, Camera, etc.
  3. Revoke unnecessary permissions

4. Location Services

Per-App Location Settings

For each app, choose:

  • Never – No location access
  • Ask Next Time Or When I Share – Prompts each time
  • While Using the App – Access only when app is open
  • Always – Background access (use sparingly)

Precise vs. Approximate Location

  1. Go to Settings > Privacy & Security > Location Services
  2. Select an app
  3. Toggle Precise Location off for approximate area sharing

Significant Locations

  1. Go to Settings > Privacy & Security > Location Services > System Services
  2. Tap Significant Locations
  3. View, toggle off, or clear history

5. Lock and Hide Apps

How to Lock an App

  1. Touch and hold the app icon on Home Screen
  2. Tap Require Face ID (or Touch ID/Passcode)
  3. Confirm your choice

How to Lock and Hide an App

  1. Touch and hold the app icon
  2. Select Hide and Require Face ID
  3. App moves to Hidden folder in App Library

To access hidden apps:

  1. Swipe left to App Library
  2. Scroll to bottom, tap Hidden folder
  3. Authenticate with Face ID/Touch ID

What Happens When Apps Are Locked

  • No notification previews
  • Hidden from Spotlight search
  • Hidden from Siri suggestions
  • Call history from locked apps is hidden

Integration with Stolen Device Protection

When Stolen Device Protection is enabled, locked apps can only be opened with Face ID/Touch ID—passcode fallback is disabled.


6. Safari Privacy Settings

Advanced Tracking and Fingerprinting Protection (NEW in iOS 26)

iOS 26 expands anti-fingerprinting protection to all browsing, not just Private Browsing:

  1. Go to Settings > Apps > Safari > Advanced
  2. Set Advanced Tracking and Fingerprinting Protection to All Browsing

This normalizes browser data to make your device look generic to tracking scripts, significantly reducing fingerprinting effectiveness.

Private Browsing with Face ID Lock

  1. Go to Settings > Apps > Safari
  2. Enable Require Face ID to Unlock Private Browsing

Hide IP Address

  1. Go to Settings > Apps > Safari > Hide IP Address
  2. Choose:
    • Trackers Only – Hides IP from known trackers
    • Trackers and Websites – Hides IP from all sites (requires iCloud+ Private Relay)

Intelligent Tracking Prevention

  1. Go to Settings > Apps > Safari
  2. Enable Prevent Cross-Site Tracking

Fraudulent Website Warning

  1. Go to Settings > Apps > Safari
  2. Enable Fraudulent Website Warning

iOS 26 automatically strips tracking parameters (UTMs) from URLs in Safari Private Browsing, Messages, and Mail.

Note

WebKit is by a wide margin the most-patched component of iOS: 19 of the ~29 fixes in iOS 26.6.1 and the large majority of the ~37 in iOS 26.5.2 were WebKit bugs. Every browser on iOS uses WebKit, so this applies whichever browser you prefer — and it is why installing iOS updates promptly matters more than which browser you choose.


7. Mail Privacy Protection

Features

  • Hides your IP address from senders
  • Prevents open tracking
  • Blocks invisible tracking pixels

How to Enable

  1. Go to Settings > Apps > Mail > Privacy Protection
  2. Enable Protect Mail Activity

Or configure separately:

  • Hide IP Address
  • Block All Remote Content
Important

A bug in iOS versions before 26.4 (CVE-2026-20692) caused “Hide IP Address” and “Block All Remote Content” to silently fail, potentially leaking your IP address and loading remote tracking content. Ensure you are running iOS 26.4 or later for these settings to work correctly.


8. Passwords App

iOS 26 significantly enhances the standalone Passwords app.

New Features in iOS 26

  • Password Version History – View previous passwords for any account with timestamps
  • Secure Export – FIDO Alliance standard for moving passwords, passkeys, and verification codes to other managers
  • Automatic Passkey Upgrades – When you sign in with a password, system can create a passkey for next time
  • Credential Management Endpoints – Prompts to upgrade passwords to passkeys
  • Websites to Exclude – Manage sites where passwords shouldn’t be saved

How to Access

  1. Open the Passwords app
  2. Authenticate with Face ID/Touch ID

View Password History

  1. Open Passwords
  2. Select a saved login
  3. Tap View History (appears when multiple versions exist)

Export Passwords Securely

  1. Open Passwords
  2. Tap Settings (gear icon)
  3. Select Export Passwords
  4. Choose destination app (uses encrypted FIDO Alliance format)

Security Alerts

The app warns about:

  • Credentials in known data breaches
  • Weak passwords
  • Reused passwords

Acting on those warnings is still manual. Automatic password rotation was announced for iOS 27 but did not ship; Apple deferred it to a future update on September 11, 2026.

Note

A CloudKit bug in iOS 26.4 broke password syncing via the Passwords app. If passwords are missing or stale on some devices, update all devices to iOS 26.4.1 or later and verify that credentials sync correctly.


9. Advanced Data Protection for iCloud

End-to-end encryption for the majority of your iCloud data.

What It Protects (25 categories total)

  • iCloud Backup (including Messages)
  • iCloud Drive
  • Photos
  • Notes
  • Reminders
  • Safari Bookmarks
  • Voice Memos
  • Freeform boards
  • And more…

Cannot be encrypted:

  • iCloud Mail, Contacts, Calendars (due to interoperability requirements)

How to Enable

  1. Go to Settings > [Your Name] > iCloud
  2. Tap Advanced Data Protection
  3. Tap Turn On Advanced Data Protection
  4. Set up recovery method first:
    • Recovery Contact – Trusted person to help regain access
    • Recovery Key – 28-character code to store securely
Important
  • Apple cannot recover your data if you lose access
  • All devices must run supported OS versions
  • iCloud.com access is disabled by default

United Kingdom

Advanced Data Protection remains unavailable to new users in the United Kingdom, following Apple’s withdrawal of the feature there in 2025 under a Technical Capability Notice. Apple’s support page still states that UK users who had not already enabled it no longer have the option.

The dispute is live again: the Home Office issued a renewed, UK-only technical capability notice, and Apple filed a fresh complaint with the Investigatory Powers Tribunal in July 2026, reported in early August. The scope and exact terms of the new notice are not public, and nothing has been restored. Ten iCloud categories — Backup, Drive, Photos, Notes, Reminders, Bookmarks, Shortcuts, Voice Memos, Wallet passes and Freeform — revert to standard protection, meaning Apple holds keys that can be compelled.

If you are in the UK and this matters to you, the practical mitigations are to keep sensitive material out of iCloud entirely, or to store it in an end-to-end encrypted third-party service. iMessage, FaceTime, Health data, iCloud Keychain and payment information remain end-to-end encrypted in the UK regardless.


10. Lockdown Mode

Important

Extreme protection for users who may be targeted by sophisticated attacks. This mode significantly restricts device functionality to reduce attack surfaces, but also provides robust defense against mercenary spyware.

Who Should Use It

  • Journalists, activists, diplomats
  • High-profile individuals
  • Anyone targeted by mercenary spyware

What Lockdown Mode Does

  • Messages: Most attachments blocked
  • Web: Complex technologies disabled (JIT JavaScript)
  • FaceTime: Incoming calls blocked from unknown contacts
  • Photos: Location excluded from shared photos
  • Device: Wired connections blocked when locked
  • Wireless: 2G cellular disabled, won’t auto-join insecure Wi-Fi

How to Enable

  1. Go to Settings > Privacy & Security
  2. Scroll down and tap Lockdown Mode
  3. Tap Turn On Lockdown Mode
  4. Tap Turn On & Restart
  5. Enter your passcode

Track Record

In March 2026, an Apple spokesperson stated that Apple is not aware of any successful mercenary spyware attack against a device with Lockdown Mode enabled since the feature launched in 2022. Note the precise wording: it is a statement about what Apple knows, limited to mercenary spyware — not a guarantee that no such device has ever been compromised by any means. In April 2026, Apple further stated that Lockdown Mode protected users from a set of web-based attacks even on out-of-date iOS versions that had not received the relevant patches.

That is a strong argument for anyone with a realistic targeting risk. The cost is real — blocked attachments, broken websites, no FaceTime from unknown numbers — but it is the single most effective control available on iOS.


11. Communication Safety & Parental Controls

Enhanced Parental Controls (iOS 26)

iOS 26 significantly strengthens parental controls:

  • Child Accounts – Create or move kids into managed accounts easily
  • Communication Controls – Decide who children can text/call
  • Third-Party App Management – Control messaging in gaming and social apps
  • Unknown Number Blocking – Block calls/messages from unknown numbers
  • Age Limits – Set strict age limits for app downloads
  • Explicit Content Detection – Blurs inappropriate content in shared albums and FaceTime

Communication Safety

Protects children from sensitive content in Messages:

  1. Go to Settings > Screen Time
  2. Tap Communication Safety
  3. Toggle on Communication Safety

In iOS 27 this expands beyond nudity to blur gore and violence in Messages and FaceTime for users under 18, tied to the Child Account.

Sensitive Content Warning (Adults)

  1. Go to Settings > Privacy & Security > Sensitive Content Warning
  2. Toggle on to blur sensitive images

12. Safety Check

Quickly review and reset access you’ve granted to others.

How to Access

  1. Go to Settings > Privacy & Security
  2. Tap Safety Check

Options

Manage Sharing & Access: Granular control over individual permissions

Emergency Reset: Immediately stops all sharing, resets permissions, signs out of iCloud on other devices

Quick Exit: Instantly returns to Home Screen (progress saved)


13. Find My iPhone

How to Enable

  1. Go to Settings > [Your Name] > Find My
  2. Tap Find My iPhone
  3. Enable:
    • Find My iPhone
    • Find My Network (locate even when offline)
    • Send Last Location

Activation Lock for Parts (iOS 26)

iOS 26 extends Activation Lock to individual components (batteries, cameras, displays), making stolen parts unusable.

AirTag (2nd Generation) - iOS 26.2.1 Required

The new AirTag (released January 26, 2026) requires iOS 26.2.1 or later and includes significant security and tracking improvements:

Enhanced Finding Capabilities:

  • 50% longer Precision Finding range via second-generation Ultra Wideband chip
  • Precision Finding on Apple Watch – Works on Apple Watch Series 9+, Ultra 2+ (first time on wrist)
  • Expanded Bluetooth range – Better detection by Find My network devices
  • 50% louder speaker – Easier to locate and harder for stalkers to mask

Anti-Stalking Improvements:

  • Louder alert sounds when separated from owner’s device
  • Improved detection notifications on iPhones
  • Same separation alert timing (approximately 8 hours)

Share Item Location:

  • Securely share AirTag location with airlines for lost luggage
  • 36 airlines supported at launch, 15+ more coming
  • End-to-end encrypted sharing

How to Set Up AirTag (2nd Gen):

  1. Ensure iOS 26.2.1 is installed
  2. Bring AirTag near your iPhone
  3. Tap Connect when prompted
  4. Name your AirTag and assign an emoji
  5. Register to your Apple ID

14. Advertising and Tracking Controls

Disable Advertising Identifier

  1. Go to Settings > Privacy & Security > Tracking
  2. Toggle off Allow Apps to Request to Track

Disable Apple Personalized Ads

  1. Go to Settings > Privacy & Security > Apple Advertising
  2. Toggle off Personalized Ads

Analytics & Improvements

  1. Go to Settings > Privacy & Security > Analytics & Improvements
  2. Toggle off data sharing options

15. Apple Intelligence Privacy

On-Device Processing

Most Apple Intelligence features process data locally on your device.

Private Cloud Compute

For complex requests:

  • Uses Apple’s Private Cloud Compute
  • Data never stored on servers
  • Cryptographically verified privacy

As of iOS 27, Apple has confirmed that Private Cloud Compute runs partly on Google Cloud infrastructure alongside Apple’s own hardware. Apple’s position is that the cryptographic guarantees do not depend on whose data centre the silicon sits in — the verification model is the same. Whether that changes your assessment is a judgement about trust boundaries, not about the cryptography.

Control AI Learning

  1. Go to Settings > Apple Intelligence & Siri
  2. Scroll to Apps
  3. Toggle off Learn from this App for sensitive apps

Reviewing What Left Your Device

Apple Intelligence keeps a historical report of requests that were sent to Private Cloud Compute rather than handled on device. Check it periodically if you want to know how much of your Siri and writing-tools activity is actually leaving the iPhone. Note that a bug in the iOS 27 betas caused this report to under-report PCC usage; it was fixed before release, but it is a reminder that transparency reports are software too.


16. Wi-Fi Aware & Network Security (NEW in iOS 26)

Wi-Fi Aware

A new peer-to-peer networking framework allowing secure connections without access points:

  • Direct encrypted links between devices
  • Ideal for file transfers, gaming, media streaming
  • No internet connection required
  • Third-party apps can use this for secure local sharing

Post-Quantum Cryptography (iOS 26)

iOS 26 adds hybrid post-quantum key exchange to TLS connections:

  • Pairs classic elliptic curve math with lattice-based schemes
  • Protects current data against future quantum computing threats
  • Works automatically with Apple’s networking frameworks

Limit Precise Location (NEW in iOS 26.3)

Reduces the location precision available to your cellular carrier from street-level to neighborhood-level.

How to enable:

  1. Go to Settings > Privacy & Security > Location Services > System Services
  2. Tap Limit Precise Location
  3. Toggle on

Requirements:

  • iPhone 16e or iPhone Air (devices with Apple C1/C1X modem)
  • Carrier support: Boost Mobile (US), EE/BT (UK), Telekom (Germany), AIS/True (Thailand) at launch

Private Wi-Fi Address

Every network you join should use a randomized MAC address so that access points cannot build a movement profile from your device.

  1. Go to Settings > Wi-Fi
  2. Tap the i button next to a network
  3. Ensure Private Wi-Fi Address is set to Rotating (or on)

On managed devices, an administrator can lock this off with the DisableAssociationMACRandomization MDM setting — which, until iOS 26.6, was not actually being enforced. If you are on a work device and thought you had opted out of that policy, check again on 26.6 or later.

VPN and IPSec

iOS 26.6.1 fixed CVE-2026-65329, in which an attacker in a privileged network position could bypass IPSec authentication and intercept traffic. If you rely on an IPSec or IKEv2 VPN — including many corporate VPNs — that fix is carried forward in iOS 26.7 and iOS 27, and it is a good reason not to sit on an older release.

Captive Assist

When you connect to public Wi-Fi by filling out a form, iOS 26 can automatically share that form information with your other Apple devices, making it easier to connect securely.


17. Wired Accessories Security (NEW in iOS 26)

Enhanced USB-C/Lightning Port Security

iOS 26 gives you explicit control over what happens when accessories connect:

How to configure:

  1. Go to Settings > Face ID & Passcode
  2. Scroll to Accessories
  3. Choose behavior:
    • Allow when unlocked (default)
    • Always ask
    • Never allow

Why This Matters

  • Malicious cables can extract data while appearing to charge
  • Compromised chargers in public places pose real risks
  • You now get immediate notification when a cable tries to do more than charge
  • Stops “juice jacking” attacks at airports, hotels, and other public charging stations

iOS 26.5.2 patched CVE-2026-43807 in MobileAccessoryUpdater, a flaw exploitable by a malicious accessory, and iOS 26.6 patched CVE-2026-43753 in DriverKit, where physical access to a locked device could reveal sensitive information. Accessories are a live attack surface, not a theoretical one — set this to Always ask.


18. AirDrop Security (NEW in iOS 26.2)

One-Time AirDrop Codes

iOS 26.2 introduces secure codes for sharing with unknown contacts:

How it works:

  1. When sharing with someone not in your contacts, generate a temporary code
  2. The receiver displays the code on their device
  3. Sender enters the code to complete transfer
  4. Code is valid for 30 days for that contact

Tighter Proximity Detection

AirDrop now shows only devices within close physical proximity, reducing:

  • Accidental transfers
  • Unsolicited content (“AirDrop spam”)
  • Faster peer-to-peer connections in crowded areas

19. Notification Privacy

Notifications are one of the most under-considered leak channels on iOS. Preview text is rendered on the lock screen without authentication, and — until iOS 26.4.2 — deleted notifications could persist in the on-device database long after the message, and even the app, were gone (CVE-2026-28950).

Hide Previews

  1. Go to Settings > Notifications > Show Previews
  2. Select When Unlocked, or Never for the strongest setting

You can also do this per app: Settings > Notifications > [App] > Show Previews.

Locked Apps Hide Their Notifications

An app locked with Face ID (see section 5) shows no notification previews at all, and is hidden from Spotlight and Siri suggestions. This is the cleanest way to keep a specific messaging app off the lock screen.

Block List Limits

As of iOS 26.6, iOS warns you when your blocked-contacts list is full and you must remove an entry before adding another. If you are managing sustained harassment, be aware that the list is finite and plan around it — carrier-level blocking and Silence Unknown Callers (Settings > Apps > Phone > Silence Unknown Callers) scale better than blocking numbers one at a time.


20. Additional Security Recommendations

Lock Screen Security

Disable Control Center from lock screen:

  1. Go to Settings > Face ID & Passcode
  2. Under Allow Access When Locked, toggle off:
    • Control Center
    • Notification Center
    • USB Accessories

Automatic Software Updates

  1. Go to Settings > General > Software Update
  2. Tap Automatic Updates
  3. Enable all options including Security Responses & System Files

Liquid Glass Opacity (iOS 26)

For better readability and reduced glare:

  1. Go to Settings > Display & Brightness > Liquid Glass
  2. Choose Clear (sharper) or Tinted (softer, less glare)

Restart After Security Updates

After installing any security update, restart your device. Some spyware lives only in volatile memory and is cleared by a reboot.

Erase Data After Failed Attempts

  1. Go to Settings > Face ID & Passcode
  2. Enable Erase Data (erases after 10 failed passcode attempts)

Quick Reference: Essential Settings Checklist

SettingLocationRecommended
iOS versionSettings > General > Software Update✅ iOS 27, or iOS 26.7 if staying on 26
Face ID/Touch IDSettings > Face ID & Passcode✅ Enable
Strong PasscodeSettings > Face ID & Passcode✅ Alphanumeric
Two-Factor AuthenticationSettings > [Name] > Sign-In & Security✅ Enable
Stolen Device ProtectionSettings > Face ID & Passcode✅ Verify it is on
App TrackingSettings > Privacy & Security > Tracking❌ Disable
Advanced Tracking ProtectionSettings > Apps > Safari > Advanced✅ All Browsing
Mail PrivacySettings > Apps > Mail > Privacy Protection✅ Enable
Advanced Data ProtectionSettings > [Name] > iCloud > Advanced Data Protection✅ Enable (not available to new UK users)
Find MySettings > [Name] > Find My✅ Enable
Automatic UpdatesSettings > General > Software Update✅ Enable
Wired AccessoriesSettings > Face ID & Passcode > Accessories⚙️ Always Ask
Lock Screen PreviewsSettings > Notifications > Show Previews⚙️ When Unlocked or Never
Private Wi-Fi AddressSettings > Wi-Fi > (i) next to network✅ Rotating
Lockdown ModeSettings > Privacy & Security > Lockdown Mode⚙️ If you may be targeted
Hide Location (iOS 27)Find My app > person’s card⚙️ Know it is silent both ways

Conclusion

iOS 27 shipped on September 14, 2026, alongside iOS 26.7 for anyone staying on the previous major version. The iOS 26 cycle as a whole has been Apple’s most active security year on record — well over 350 vulnerabilities patched across sixteen releases, before iOS 27 added a hundred more. Key priorities:

  1. Move to iOS 27, or to iOS 26.7 if you are not ready – Both carry the September 14 fixes. Turn on Automatic Updates so the next one installs itself. If you intend to stay on 26.7, remember Apple has promised nothing about how long that track lives.
  2. Do not run anything older than iOS 26.4.2 – That release fixed the notification-retention flaw (CVE-2026-28950) used to recover supposedly deleted messages from seized phones.
  3. If a device cannot see updates, check iOS 26.6.2 – The September 8 release fixed a bug that blocked update downloads over cellular. A phone that only has mobile data could otherwise be silently stuck.
  4. Enable Lockdown Mode if you may be targeted – Apple said in 2026 that it is aware of no successful mercenary spyware attack against a device running it, and that it blocked real web attacks even on unpatched systems.
  5. Verify Stolen Device Protection is enabled – On by default since iOS 26.4/26.4.1. Keep an offline recovery key, because it can lock you out too.
  6. Turn on Advanced Data Protection – End-to-end encrypts your iCloud data. Still unavailable to new users in the UK, and the dispute is back before the Investigatory Powers Tribunal.
  7. Set Show Previews to When Unlocked or Never – Notifications are the leak channel people forget.
  8. Set Wired Accessories to Always Ask – Two 2026 CVEs involved malicious accessories and physical access to locked devices.
  9. Enable Advanced Tracking Protection for All Browsing – Every iOS browser uses WebKit, and WebKit is where most of the patches land.
  10. Look for the lock icon on RCS chats – Confirms end-to-end encryption is active for that conversation; otherwise treat the chat as unencrypted in transit.
  11. Restart after updates – Clears memory-resident threats.

On iOS 27 specifically: accept the Trust Insights prompt when your bank or payment app asks for it, and be aware that turning it off may come with a cooldown. If you share your location with anyone, understand that Hide Location is silent in both directions. And do not wait for automatic password rotation — it was deferred, so weak and breached passwords are still yours to fix.


Last updated: September 15, 2026 | Applies to iOS 27 and iOS 26.7 Device requirements: iPhone 11 or later (A13 Bionic chip minimum) for both tracks iPadOS 27 drops several iPads that iPadOS 26.7 still supports AirTag (2nd Generation) requires iOS 26.2.1 or later Limit Precise Location requires iPhone 16e or iPhone Air Legacy security patches: iOS 18.7.10 (August 17, 2026) is the most recent for older devices Automatic password rotation and Suggestions in Messages were deferred out of the iOS 27 release