APPLE-SA-03-24-2026-8 visionOS 26.4
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。 首先,我需要快速浏览一下这篇文章。看起来这是一份苹果的安全公告,针对visionOS 26.4版本的更新。里面提到了多个安全漏洞,涉及不同的组件,比如802.1X、Accounts、Audio等等。每个漏洞都有CVE编号和发现者的信息。 接下来,我需要提取关键信息:苹果发布了visionOS 26.4更新,修复了多个安全漏洞,涉及网络、音频、媒体等多个方面。这些漏洞可能导致数据泄露、系统崩溃等问题。 然后,我要把这些信息浓缩到100字以内。确保涵盖主要点:更新版本、修复的问题类型、影响范围以及安全建议。 最后,检查一下语言是否简洁明了,没有使用任何开头的套话,直接描述内容。 </think> Apple发布visionOS 26.4更新,修复了多个安全漏洞,涉及网络认证、用户数据访问、音频处理等方面。这些问题可能导致数据泄露或系统崩溃。建议用户尽快更新以提升安全性。 2026-3-29 03:11:8 Author: seclists.org(查看原文) 阅读量:5 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 24 Mar 2026 17:04:31 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-03-24-2026-8 visionOS 26.4

visionOS 26.4 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126799.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

802.1X
Available for: Apple Vision Pro (all models)
Impact: An attacker in a privileged network position may be able to
intercept network traffic
Description: An authentication issue was addressed with improved state
management.
CVE-2026-28865: Héloïse Gollier and Mathy Vanhoef (KU Leuven)

Accounts
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-28877: Rosyna Keller of Totally Not Malicious Software

Audio
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: A use-after-free issue was addressed with improved memory
management.
CVE-2026-28879: Justin Cohen of Google

Audio
Available for: Apple Vision Pro (all models)
Impact: An attacker may be able to cause unexpected app termination
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-28822: Jex Amro

CoreMedia
Available for: Apple Vision Pro (all models)
Impact: Processing an audio stream in a maliciously crafted media file
may terminate the process
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
CVE-2026-20690: Hossein Lotfi (@hosselot) of Trend Micro Zero Day
Initiative

CoreUtils
Available for: Apple Vision Pro (all models)
Impact: A user in a privileged network position may be able to cause a
denial-of-service
Description: A null pointer dereference was addressed with improved
input validation.
CVE-2026-28886: Etienne Charron (Renault) and Victoria Martini (Renault)

Crash Reporter
Available for: Apple Vision Pro (all models)
Impact: An app may be able to enumerate a user's installed apps
Description: A privacy issue was addressed by removing sensitive data.
CVE-2026-28878: Zhongcheng Li from IES Red Team

curl
Available for: Apple Vision Pro (all models)
Impact: An issue existed in curl which may result in unintentionally
sending sensitive information via an incorrect connection
Description: This is a vulnerability in open source code and Apple
Software is among the affected projects. The CVE-ID was assigned by a
third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2025-14524

DeviceLink
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was
addressed with improved path validation.
CVE-2026-28876: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

GeoServices
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: An information leakage was addressed with additional
validation.
CVE-2026-28870: XiguaSec

iCloud
Available for: Apple Vision Pro (all models)
Impact: An app may be able to enumerate a user's installed apps
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-28880: Zhongcheng Li from IES Red Team
CVE-2026-28833: Zhongcheng Li from IES Red Team

ImageIO
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: This is a vulnerability in open source code and Apple
Software is among the affected projects. The CVE-ID was assigned by a
third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2025-64505

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to disclose kernel memory
Description: A logging issue was addressed with improved data redaction.
CVE-2026-28868: 이동하 (Lee Dong Ha of BoB 0xB6)

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to leak sensitive kernel state
Description: This issue was addressed with improved authentication.
CVE-2026-28867: Jian Lee (@speedyfriend433)

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-20698: DARKNAVY (@DarkNavyOrg)

libxpc
Available for: Apple Vision Pro (all models)
Impact: An app may be able to enumerate a user's installed apps
Description: This issue was addressed with improved checks.
CVE-2026-28882: Ilias Morad (A2nkF) of Voynich Group, Duy Trần
(@khanhduytran0), @hugeBlack

Printing
Available for: Apple Vision Pro (all models)
Impact: An app may be able to break out of its sandbox
Description: A path handling issue was addressed with improved
validation.
CVE-2026-20688: wdszzml and Atuin Automated Vulnerability Discovery
Engine

Sandbox Profiles
Available for: Apple Vision Pro (all models)
Impact: An app may be able to fingerprint the user
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-28863: Gongyu Ma (@Mezone0)

Security
Available for: Apple Vision Pro (all models)
Impact: A local attacker may gain access to user's Keychain items
Description: This issue was addressed with improved permissions
checking.
CVE-2026-28864: Alex Radocea

Siri
Available for: Apple Vision Pro (all models)
Impact: An attacker with physical access to a locked device may be able
to view sensitive user information
Description: The issue was addressed with improved authentication.
CVE-2026-28856: an anonymous researcher

UIFoundation
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause a denial-of-service
Description: A stack overflow was addressed with improved input
validation.
CVE-2026-28852: Caspian Tarafdar

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may prevent Content
Security Policy from being enforced
Description: This issue was addressed through improved state management.
WebKit Bugzilla: 304951
CVE-2026-20665: webb

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may bypass Same
Origin Policy
Description: A cross-origin issue in the Navigation API was addressed
with improved input validation.
WebKit Bugzilla: 306050
CVE-2026-20643: Thomas Espach

WebKit
Available for: Apple Vision Pro (all models)
Impact: A malicious website may be able to access script message
handlers intended for other origins
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 307014
CVE-2026-28861: Hongze Wu and Shuaike Dong from Ant Group Infrastructure
Security Team

WebKit
Available for: Apple Vision Pro (all models)
Impact: A malicious website may be able to process restricted web
content outside the sandbox
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 308248
CVE-2026-28859: greenbynox, Arni Hardarson

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 306136
CVE-2026-20664: Daniel Rhea, Söhnke Benedikt Fischedick (Tripton),
Emrovsky & Switch, Yevhen Pervushyn
WebKit Bugzilla: 307723
CVE-2026-28857: Narcis Oliveras Fontàs, Söhnke Benedikt Fischedick
(Tripton), Daniel Rhea, Nathaniel Oh (@calysteon)

WebKit Sandboxing
Available for: Apple Vision Pro (all models)
Impact: A maliciously crafted webpage may be able to fingerprint the
user
Description: An authorization issue was addressed with improved state
management.
WebKit Bugzilla: 306827
CVE-2026-20691: Gongyu Ma (@Mezone0)

Additional recognition

AirPort
We would like to acknowledge Yashar Shahinzadeh, Saman Ebrahimnezhad,
Amir Safari, Omid Rezaii for their assistance.

Bluetooth
We would like to acknowledge Hamid Mahmoud for their assistance.

Captive Network
We would like to acknowledge Kun Peeks (@SwayZGl1tZyyy) for their
assistance.

CipherML
We would like to acknowledge Nils Hanff (@[email protected]) of
Hasso Plattner Institute for their assistance.

CloudAttestation
We would like to acknowledge Suresh Sundaram, Willard Jansen for their
assistance.

CoreUI
We would like to acknowledge Peter Malone for their assistance.

Find My
We would like to acknowledge Salemdomain for their assistance.

GPU Drivers
We would like to acknowledge Jian Lee (@speedyfriend433) for their
assistance.

ICU
We would like to acknowledge Jian Lee (@speedyfriend433) for their
assistance.

Kernel
We would like to acknowledge DARKNAVY (@DarkNavyOrg), Kylian Boulard De
Pouqueville From Fuzzinglabs, Patrick Ventuzelo From Fuzzinglabs, Robert
Tran, Suresh Sundaram for their assistance.

libarchive
We would like to acknowledge Andreas Jaegersberger & Ro Achterberg of
Nosebeard Labs, Arni Hardarson for their assistance.

libc
We would like to acknowledge Vitaly Simonovich for their assistance.

Libnotify
We would like to acknowledge Ilias Morad (@A2nkF_) for their assistance.

LLVM
We would like to acknowledge Nathaniel Oh (@calysteon) for their
assistance.

Messages
We would like to acknowledge JZ for their assistance.

MobileInstallation
We would like to acknowledge Gongyu Ma (@Mezone0) for their assistance.

Music
We would like to acknowledge Mohammad Kaif (@_mkahmad | kaif0x01) for
their assistance.

Notes
We would like to acknowledge Dawuge of Shuffle Team and Hunan University
for their assistance.

ppp
We would like to acknowledge Dave G. for their assistance.

Quick Look
We would like to acknowledge Wojciech Regula of SecuRing
(wojciechregula.blog), an anonymous researcher for their assistance.

Safari
We would like to acknowledge @RenwaX23, Farras Givari, Syarif Muhammad
Sajjad, Yair for their assistance.

Shortcuts
We would like to acknowledge Waleed Barakat (@WilDN00B) and Paul
Montgomery (@nullevent) for their assistance.

Siri
We would like to acknowledge Anand Mallaya, Tech consultant, Anand
Mallaya and Co., Harsh Kirdolia, Hrishikesh Parmar of Self-Employed for
their assistance.

Time Zone
We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from
Safran Mumbai India for their assistance.

UIKit
We would like to acknowledge AEC, Abhay Kailasia (@abhay_kailasia) from
Safran Mumbai India, Bishal Kafle (@whoisbishal.k), Carlos Luna (U.S.
Department of the Navy), Dalibor Milanovic, Daren Goodchild, JS De
Mattei, Maxwell Garn, Zack Tickman, fuyuu12, incredincomp for their
assistance.

Wallet
We would like to acknowledge Zhongcheng Li from IES Red Team of
ByteDance for their assistance.

Web Extensions
We would like to acknowledge Carlos Jeurissen, Rob Wu (robwu.nl) for
their assistance.

WebKit
We would like to acknowledge Vamshi Paili for their assistance.

WebKit Process Model
We would like to acknowledge Joseph Semaan for their assistance.

Wi-Fi
We would like to acknowledge Kun Peeks (@SwayZGl1tZyyy), an anonymous
researcher for their assistance.

Wi-Fi Connectivity
We would like to acknowledge Alex Radocea of Supernetworks, Inc for
their assistance.

Widgets
We would like to acknowledge Marcel Voß, Mitul Pranjay, Serok Çelik for
their assistance.

Instructions on how to update visionOS are available
at https://support.apple.com/kb/HT214009

To check the software version on your Apple Vision Pro,
open the Settings app and choose General > About.

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmnDI2MACgkQ4Ifiq8DH
7PWuKA//atH169ExbPVZu209fB3hm4y/XOyLPJlsDdr4cNGaQzy7d2zj9wyzdpMk
KWiLrt9z1Ed9LPgFMVRDcxseu386lylzv1cFWPSTvVxiG/f+0DQoXvGqfnrM4VtH
679lCtPN04GgMADBTP7moZRIlvu04BQ9tkhW8L3KEoeoTu60UV4DJ0B/kU03t/Nh
nOJfz18FjKUFUTZcYIr+AcpYmGqUgw21hLvPtdufMhfvckn1gUnsm097ELJ1fSZT
gzJya8HMOzEPzi9zoQXoC9r8ph4B0FIHaoqWi5Ratq8w1SvJo+gzZxT6OOcnGiwN
wZenOsMx03nOyNg0nImB/AHrZiDhLjai60IbwPrZhGr1eV2TkVTKYmf34KRHgFs4
/KAbw9QF6h+MdAdJYKBEH8DvAaRiYGmE3eW5URJIkwWbX/FQVl8yfuPHY92gnUyX
sJCQ9yM0y3da3fy9RaZmSqsOXegnnF3danmLZ+qr8yjke2YynMkmP8XBZxBuIrwF
qCukRmbf8hu9JJkkgAFFchhEyHIOMEz3vVcqR9m0xfXqDYXufAyX3HEFR3595tqX
mqv2uBBZd/BJWC5dlJG2HNNY7SZOLfULt6CmxlEAzkXav6z0o49NHAX9hKm8A1fs
wIW/zZjx/r6NCS+V3z4efAI+NNAjZbU2qbxpMJpd7kz2bg8kO+k=
=fTpw
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • APPLE-SA-03-24-2026-8 visionOS 26.4 Apple Product Security via Fulldisclosure (Mar 28)

文章来源: https://seclists.org/fulldisclosure/2026/Mar/23
如有侵权请联系:admin#unsafe.sh