APPLE-SA-09-14-2026-8 visionOS 27
Full Disclosuremailing list archivesFrom: Apple Product Security via Fulldisclos 2026-9-22 18:31:31 Author: seclists.org(查看原文) 阅读量:5 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 14 Sep 2026 15:09:24 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-09-14-2026-8 visionOS 27

visionOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149038.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted image may lead to unexpected
process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-86882: Peter Malone

APFS
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84523: Cem Onat Karagun, an anonymous researcher

App Store
Available for: Apple Vision Pro (all models)
Impact: A local app may be able to read a persistent account identifier
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86888: Zhongcheng Li (CK01)

Apple Account
Available for: Apple Vision Pro (all models)
Impact: An app may be able to use the Sign In With Apple authentication
flow to access the user's Apple Account
Description: An authentication issue was addressed with improved state
management.
CVE-2026-20683: Dem0ns (@天府简易信工作室), Abdelhak Kherroubi, Jasminder Pal
Singh, Lehan Dilusha Jayasingha (Sri Lanka)

AppleAVD
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-65407: Franco Belman at Blackwing Intelligence

Audio
Available for: Apple Vision Pro (all models)
Impact: An app may be able to leak sensitive user information
Description: A logic issue was addressed with improved checks.
CVE-2026-65339: Mustafa Calap (@ordinal0, dbg.re), Meta Red Team X - Nik
Tsytsarkin

Authentication Services
Available for: Apple Vision Pro (all models)
Impact: An app may be able to delete credentials stored in Keychain
Description: This issue was addressed by removing the vulnerable code.
CVE-2026-86905: Ilya Andr (andrd3v)

AuthKit
Available for: Apple Vision Pro (all models)
Impact: A local app may be able to read a persistent account identifier
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84583: Zhongcheng Li from IES Red Team

AVEVideoEncoder
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved checks.
CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic
Research

AVEVideoEncoder
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-84616: Peter Malone

AVEVideoEncoder
Available for: Apple Vision Pro (all models)
Impact: A sandboxed app may be able to execute arbitrary code with
kernel privileges
Description: A race condition was addressed with improved state
management.
CVE-2026-84607: Ruslan Dautov

BackgroundAssets
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved validation.
CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security

Bluetooth
Available for: Apple Vision Pro (all models)
Impact: A remote attacker may be able to cause unexpected app
termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65414

Bluetooth
Available for: Apple Vision Pro (all models)
Impact: An app may gain unauthorized access to Bluetooth
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84560: an anonymous researcher

CloudKit
Available for: Apple Vision Pro (all models)
Impact: A local app may be able to read a persistent account identifier
Description: An information disclosure issue was addressed with improved
state management.
CVE-2026-86895: Stanislav Jelezoglo

CloudKit
Available for: Apple Vision Pro (all models)
Impact: An app may be able to read device name
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86893: Heiner Gerdes

copyfile
Available for: Apple Vision Pro (all models)
Impact: An archive may be able to bypass Gatekeeper
Description: A file quarantine bypass was addressed with additional
checks.
CVE-2026-65399: Rishabh Jain (rjcyber) of cyberplanet, Pasquale Scola,
an anonymous researcher

CoreMedia
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted image may lead to arbitrary
code execution
Description: A memory corruption issue was addressed by removing the
vulnerable code.
CVE-2026-64752: Nik Tsytsarkin

CoreMedia
Available for: Apple Vision Pro (all models)
Impact: A sandboxed process may be able to circumvent sandbox
restrictions
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-86876: Chris Bailey - Short Circuit

CoreMedia
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted video file may lead to
unexpected app termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65344: Siyeong kim

CoreML
Available for: Apple Vision Pro (all models)
Impact: A sandboxed app may be able to access restricted files
Description: A permissions issue was addressed with improved path
validation.
CVE-2026-84624: AL Najafi, tamdao

CoreText
Available for: Apple Vision Pro (all models)
Impact: Processing web content may lead to a denial-of-service
Description: A null pointer dereference was addressed with improved
input validation.
CVE-2026-65412: Pavan Nallamothu

CoreText
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84596: ret2happy, Meta Product Security

CoreUI
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re)

CoreUI
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted image may lead to unexpected
app termination
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-84571: stratan (@5tratan), Peter Malone

CoreUI
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted asset catalog may lead to
unexpected process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84511: Rahul Raj, stratan (@5tratan)

DeviceCheck
Available for: Apple Vision Pro (all models)
Impact: An app may be able to read persistent device identifiers
Description: An authorization issue was addressed with improved access
control.
CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill
(@[email protected])

File Bookmark
Available for: Apple Vision Pro (all models)
Impact: An app may be able to modify a file it only had permission to
read
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-43785: Junyeong Lee (jylab.github.io), Merrick Hare, Aditya
Kumar, John Nzyuko Uvyu, Narendra Singh (@_3P1C)

file_cmds
Available for: Apple Vision Pro (all models)
Impact: Extracting a maliciously crafted archive may allow an attacker
to write arbitrary files
Description: A path handling issue was addressed with improved
validation.
CVE-2026-84534: Geoffrey Lovelace

FontParser
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted font file may lead to
unexpected app termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84524: an anonymous researcher

FontParser
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-84597: Nik Tsytsarkin

Foundation
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause a denial of service
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and
Anthropic Research

Graphics
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg),
Jiyong Yang

iCloud
Available for: Apple Vision Pro (all models)
Impact: An app may be able to identify a user across reinstalls
Description: A privacy issue was addressed with improved handling of
identifiers.
CVE-2026-84606: Ilya Andr (andrd3v)

ImageIO
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted image may result in disclosure
of process memory
Description: An uninitialized memory issue was addressed with improved
memory initialization.
CVE-2026-84564: Justin O'Leary

ImageIO
Available for: Apple Vision Pro (all models)
Impact: Processing an image may lead to a denial-of-service
Description: The issue was addressed with improved checks.
CVE-2026-65347: Geonha Lee (@leegn4a)

ImageIO
Available for: Apple Vision Pro (all models)
Impact: Processing an image may lead to arbitrary code execution
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-65346: Meta Red Team X - Nik Tsytsarkin

ImageIO
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted image may result in memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan

IOGPUFamily
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: The issue was addressed with improved memory handling.
CVE-2026-64788: an anonymous researcher, f00l (@PPPF00L) and
3ndy1(@_3ndy1) and Minghao Lin@Y1nkoc and 云散花折, Arjanit Isufi

IOKit
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영

IOMobileFrameBuffer
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
CVE-2026-65398: Chris Bailey - Short Circuit, Mustafa Calap (@ordinal0,
dbg.re), David Strnadel, Meta Red Team X - Nik Tsytsarkin
CVE-2026-64736: Ruslan Dautov, hxr1

IOSurfaceAccelerator
Available for: Apple Vision Pro (all models)
Impact: An app may be able to leak sensitive kernel state
Description: An information leakage was addressed with additional
validation.
CVE-2026-64760: an anonymous researcher, Seiji Sakurai (@HeapSmasher),
Franco Belman at Blackwing Intelligence

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-28968: genter0, Svetoslav Stolarov & Aisa Fox, Josh Maine of
Calif.io, Dun

Kernel
Available for: Apple Vision Pro (all models)
Impact: A local user may be able to cause unexpected system termination
or read kernel memory
Description: A race condition was addressed with additional validation.
CVE-2026-65415: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Ryan Hileman via Xint Code (xint.io)

Kernel
Available for: Apple Vision Pro (all models)
Impact: A remote attacker may be able to cause unexpected system
termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-65343: Drinor Selmanaj (Sentry), Surya Narayan Kushwaha

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination or
read kernel memory
Description: An out-of-bounds read was addressed with improved input
validation.
CVE-2026-65349: an anonymous researcher

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A double free issue was addressed with improved memory
management.
CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security
CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2026-65377: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Ye Zhang (@VAR10CK) of Baidu Security

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app with root privileges may be able to read uninitialized
kernel memory
Description: A memory initialization issue was addressed with improved
memory handling.
CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.)

Kernel
Available for: Apple Vision Pro (all models)
Impact: A malicious app may be able to gain root privileges
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-43689: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

Kernel
Available for: Apple Vision Pro (all models)
Impact: Connecting to a malicious NFS server may disclose kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43687: R4mbb of KRsecurity, Peter Malone

Kernel
Available for: Apple Vision Pro (all models)
Impact: Connecting to a malicious NFS server may lead to kernel memory
corruption
Description: A use-after-free issue was addressed with improved memory
management.
CVE-2026-43686: Peter Malone

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to determine kernel memory layout
Description: A memory initialization issue was addressed with improved
memory handling.
CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to disclose kernel memory
Description: An information disclosure issue was addressed with improved
memory management.
CVE-2026-84530: Vladislav Shevchenko (Positive Technologies)

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-84521: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong
and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple Vision Pro (all models)
Impact: A local user may be able to cause unexpected system termination
or read kernel memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A race condition was addressed with improved state
handling.
CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to disclose kernel memory
Description: An out-of-bounds read was addressed with improved input
validation.
CVE-2026-86903: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-65330: Ashish Kunwar, Mikhail Lozhnikov of Positive
Technologies, Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan
Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-28935: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause unexpected system termination
Description: A type confusion issue was addressed with improved checks.
CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

libarchive
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: A heap buffer overflow was addressed with improved bounds
checking.
CVE-2026-86870: Kitten Food

Managed Configuration
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved handling of
files.
CVE-2026-86883: Sindre Sorhus, Morris Richman (@morrisinlife), Stuart
Wallace, Tristan Brennan

MediaRemote
Available for: Apple Vision Pro (all models)
Impact: A sandboxed app may be able to access the System Keychain
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84628: Myeonghun Pak, Nathaniel Oh (@calysteon), Alan Banderas
(@creeper4004)

MobileBackup
Available for: Apple Vision Pro (all models)
Impact: An app may be able to modify protected parts of the file system
Description: A path handling issue was addressed with improved
validation.
CVE-2026-65411: Rodolphe Brunetti (@eisw0lf) of Lupus Nova

Model I/O
Available for: Apple Vision Pro (all models)
Impact: Opening a maliciously crafted file may lead to unexpected
process termination
Description: A buffer overflow was addressed with improved size
validation.
CVE-2026-84497: Yiğit Can YILMAZ (@yilmazcanyigit)

Music
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84615: Stanislav Jelezoglo

NetworkExtension
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos

NetworkExtension
Available for: Apple Vision Pro (all models)
Impact: An app may be able to identify what other apps a user has
installed
Description: An information disclosure issue was addressed with improved
state management.
CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team

Photos Storage
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84491: an anonymous researcher

Photos Storage
Available for: Apple Vision Pro (all models)
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-84629: Stanislav Jelezoglo

RealityKit
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-28966: stratan (@5tratan)

RealityKit
Available for: Apple Vision Pro (all models)
Impact: Opening a maliciously crafted file may cause unexpected process
termination or disclose process memory
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-84532: Hongsik Kim (mnur), stratan (@5tratan)

Reminders
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
CVE-2026-65403: Rahul Raj

Safe Browsing
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-86897: Stuart Wallace

Sandbox
Available for: Apple Vision Pro (all models)
Impact: An app may be able to bypass network restrictions
Description: A logic issue was addressed with improved validation.
CVE-2026-84551: Issa Sancho

Sandbox Profiles
Available for: Apple Vision Pro (all models)
Impact: An app may be able to fingerprint the user
Description: A permissions issue was addressed with additional sandbox
restrictions.
CVE-2026-84625: Ilya Andr (andrd3v) of Positive Technologies, CJ Vana

Sandbox Profiles
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84603: Gongyu Ma (@Mezone0), CJ Vana, Stanislav Jelezoglo

SceneKit
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted file may result in disclosure
of process memory
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84487: stratan (@5tratan), Dhiyanesh Selvaraj (@redroot97),
Peter Malone

SceneKit
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: The issue was addressed with improved memory handling.
CVE-2026-84632: Peter Malone

SceneKit
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84620: Peter Malone

SceneKit
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter
Malone
CVE-2026-84611: Nathaniel Oh (@calysteon)

SceneKit
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted 3D scene may lead to unexpected
process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84526: stratan (@5tratan)

Security
Available for: Apple Vision Pro (all models)
Impact: An attacker with a compromised intermediate certificate
authority may be able to issue certificates with arbitrary extended key
usages
Description: A certificate validation issue was addressed with improved
certificate validation.
CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier,
Filip Olszak

Shortcuts
Available for: Apple Vision Pro (all models)
Impact: A malicious shortcut may be able to send messages without user
confirmation
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84600: Owen Pawling (@owenpawling)

Software Update
Available for: Apple Vision Pro (all models)
Impact: An app may be able to modify protected system files
Description: A permissions issue was addressed with improved path
validation.
CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team

SpringBoard
Available for: Apple Vision Pro (all models)
Impact: An app may be able to cause a denial-of-service
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-86892: Lehan Dilusha Jayasingha

Symptom Framework
Available for: Apple Vision Pro (all models)
Impact: A malicious application may be able to determine a user's
current location
Description: A privacy issue was addressed with improved private data
redaction for log entries.
CVE-2026-84513: Sindre Sorhus

TCC
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom

Time Zone
Available for: Apple Vision Pro (all models)
Impact: An app may be able to bypass certain Privacy preferences
Description: A privacy issue was addressed by removing sensitive data.
CVE-2026-86887: an anonymous researcher

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
WebKit Bugzilla: 317632
CVE-2026-64784: Janggoon Lee of Out of Bounds, OpenAI Codex Security -
Amy Burnett

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected process termination
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 310457
CVE-2026-84635: Souta Sugiyama

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 313452
CVE-2026-43795: wwwlk
WebKit Bugzilla: 318348
CVE-2026-65338: OpenAI Codex Security - Amy Burnett

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 318405
CVE-2026-65341: Henock Habte

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A memory corruption vulnerability was addressed with
improved locking.
WebKit Bugzilla: 321480
CVE-2026-64782: Charles Kern, Seonwook Kim, Shubham Chaskar, lattice,
Josef Korbel

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A permissions issue was addressed by removing the
vulnerable code.
WebKit Bugzilla: 315121
CVE-2026-64753: Viggo Lekdorf

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 321484
CVE-2026-64781: Thomas Guillem

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: This issue was addressed through improved state management.
WebKit Bugzilla: 321517
CVE-2026-65351: Niels Hofmans
WebKit Bugzilla: 316996
CVE-2026-65340: Claudio Bozzato and Francesco Benvenuto of Cisco Talos,
Josef Korbel (Citadelo)
WebKit Bugzilla: 317142
CVE-2026-65337: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 317349
CVE-2026-65336: Josef Korbel
WebKit Bugzilla: 316723
CVE-2026-65335: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 317603
CVE-2026-65333: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 317450
CVE-2026-65332: Kun Peeks (@SwayZGl1tZyyy), OpenAI Codex Security - Amy
Burnett
WebKit Bugzilla: 317611
CVE-2026-65331: OpenAI Codex Security - Amy Burnett

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 316347
CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected process termination
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313703
CVE-2026-64787: 杉山 壮太, Shubham Chaskar

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 316918
CVE-2026-64780: OpenAI Codex Security - Amy Burnett

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A memory corruption issue was addressed with improved state
management.
WebKit Bugzilla: 316791
CVE-2026-65334: OpenAI Codex Security - Amy Burnett

WebKit
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: A memory corruption issue was addressed with improved
memory handling.
WebKit Bugzilla: 317317
CVE-2026-43794: Dung Do (@_piers2) of Calif.io

WebKit
Available for: Apple Vision Pro (all models)
Impact: Opening a maliciously crafted webarchive file may lead to
universal cross-site scripting
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 3182711
CVE-2026-86898: Tomi Garcia (archyxsec)

WebKit Canvas
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313935
CVE-2026-64718: Niels Hofmans, OGINOME Tomohito, an anonymous researcher

WebKit History
Available for: Apple Vision Pro (all models)
Impact: Visiting a maliciously crafted website may leak sensitive data
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 322124
CVE-2026-64778: Mohit Negi

WebKit Storage
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A memory corruption vulnerability was addressed with
improved locking.
WebKit Bugzilla: 321485
CVE-2026-64779: Tommy DeVoss from Braze Security Team (@thedawgyg),
Shubham Chaskar

WebRTC
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
WebKit Bugzilla: 322761
CVE-2026-65391: Myungyong Lee

WebRTC
Available for: Apple Vision Pro (all models)
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-65390: Kwak Kiyong (@Pwnkai23), Song Nuri

Wi-Fi Connectivity
Available for: Apple Vision Pro (all models)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84636: Jian Lee (@speedyfriend433)

Additional recognition

Accounts
We would like to acknowledge Wojciech Regula of SecuRing
(wojciechregula.blog) for their assistance.

Apple Intelligence
We would like to acknowledge an anonymous researcher for their
assistance.

AppleKeyStore
We would like to acknowledge Abdurrahman Nafi, Francisco Knabe, Karol
Mazurek (@Karmaz95) of AFINE, Somair Ansar, YOKI, an anonymous
researcher, 晓娟 谢 for their assistance.

AVEVideoEncoder
We would like to acknowledge tamdao for their assistance.

Bluetooth
We would like to acknowledge Suresh Sundaram, Youssef Ahmed Saad for
their assistance.

Calendar
We would like to acknowledge Dany Assuid, Jacob Hazak from Zero-Defense
Labs, Varik Matevosyan, stratan (@5tratan) for their assistance.

CipherML
We would like to acknowledge Nils Hanff (@[email protected]) of
Hasso Plattner Institute for their assistance.

CloudKit
We would like to acknowledge Hikerell (Loadshine Lab) for their
assistance.

Compression
We would like to acknowledge Tommy DeVoss from Braze Security Team
(@thedawgyg) for their assistance.

copyfile
We would like to acknowledge Morris Richman (@morrisinlife) and Jian Lee
(@speedyfriend433) for their assistance.

CoreAnimation
We would like to acknowledge Duy Trần (@khanhduytran0) for their
assistance.

CoreAudio
We would like to acknowledge Patrick Saif / x.com/weezerOSINT /
github.com/sai2fast for their assistance.

CoreBluetooth - LE
We would like to acknowledge Ashmit Sharma & Atul RV, Dun, Maliq
Barnard, Nicholas C. of Onymos Inc. (onymos.com), Peter Malone, Robert M
for their assistance.

CoreGraphics
We would like to acknowledge Gandalf4a of PKU-Changsha Institute for
Computing and Digital Economy for their assistance.

CoreMedia
We would like to acknowledge Chris Bailey - Short Circuit for their
assistance.

CoreText
We would like to acknowledge Jian Lee (@speedyfriend433) for their
assistance.

CoreUI
We would like to acknowledge Peter Malone for their assistance.

DataAccess
We would like to acknowledge Adetayo Adebimpe (Cyboghostginx) for their
assistance.

FaceTime
We would like to acknowledge Souhaib Naceri for their assistance.

Files
We would like to acknowledge an anonymous researcher for their
assistance.

iCloud
We would like to acknowledge 3ndy1(@_3ndy1) and moyu for their
assistance.

ImageIO
We would like to acknowledge Muhamad Syaiful, an anonymous researcher,
songbird for their assistance.

IOSurfaceAccelerator
We would like to acknowledge Chanwit Muenprakoddee (ChemIndy), Franco
Belman at Blackwing Intelligence, Iain Harkiss, an anonymous researcher,
beist, hxr1 for their assistance.

Kernel
We would like to acknowledge Bhaswanth Chigurupati, Billy Jheng Bing
Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Cem
Onat Karagun, James Duffy (@0x4A616D657344), Lyutoon, Nebula Security
(@nebusecurity), Nicolas Seriot, Peter Malone, Redon Gashi of Sentry,
Robert Tran, Xiang Li from AOSP Lab @Nankai University, an anonymous
researcher for their assistance.

LaunchServices
We would like to acknowledge Rosyna Keller of Totally Not Malicious
Software (paradisefacade.com) for their assistance.

mDNSResponder
We would like to acknowledge Anton Pakhunov, Franciszek Kalinowski
(striga.ai / isec.pl), Hannes Weissteiner, Roland Czerny, Simone Franza,
Stefan Gast and Daniel Gruss of Graz University of Technology, and
Johanna Ullrich of the Interdisciplinary Transformation University
(IT:U), Issa Sancho, Jian Zhou, 章鱼哥@aipy (aipyaipy.com) for their
assistance.

Notifications
We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from
Safran Mumbai India, Himanshu Bharti @Xpl0itme From Khatima, Jan Rokita
(rokita.me) for their assistance.

Passwords
We would like to acknowledge Catalin Lita of Moralis, Christian
Kohlschütter, David Coomber of Info-Sec.CA, Lukasz Tulikowski at
Software Cloud, Sujay Amin, an anonymous researcher for their
assistance.

Printing
We would like to acknowledge Stuart Wallace for their assistance.

Pro Res
We would like to acknowledge Meta Red Team X - Nik Tsytsarkin for their
assistance.

RemoteServiceDiscovery
We would like to acknowledge Tristan Madani (@TristanInSec) from Talence
Security, an anonymous researcher for their assistance.

Safari
We would like to acknowledge Dem0ns @天府简易信工作室 for their assistance.

Sandbox Profiles
We would like to acknowledge Lachlan Bauerochse for their assistance.

Security
We would like to acknowledge John Lussier, Roman Zabicki for their
assistance.

Share Sheet
We would like to acknowledge Atul Kishor Jaiswal, Benjamin Hornbeck for
their assistance.

Shortcuts
We would like to acknowledge Csaba Fitzl (@theevilbit) of Iru, Owen
Pawling (@owenpawling) for their assistance.

VoiceOver
We would like to acknowledge Hariji Vivek Pandey for their assistance.

WebKit
We would like to acknowledge @TristanInSec, Behzad Najjarpour Jabbari
(@_G4ru_), Big Bear, Eddy Tsalolikhin, Henock Habte, Henock Habte,
Kenneth Hsu, Maher Azzouzi, Meridian Miftari, OpenAI Codex Security -
Amy Burnett, Souta Sugiyama, Vitaly Simonovich, an anonymous researcher,
hamayanhamayan, lattice, lebr0nli of National Yang Ming Chiao Tung
University, Security and Systems Lab, ret2happy, wwwlk for their
assistance.

WebKit Canvas
We would like to acknowledge Utkarsh Pal for their assistance.

WebKit JavaScript Bindings
We would like to acknowledge hamayanhamayan for their assistance.

Wi-Fi
We would like to acknowledge E Vestavik (@Dynasty) for their assistance.

Instructions on how to update visionOS are available at
https://support.apple.com/kb/HT214009

To check the software version on your Apple Vision Pro, open the
Settings app and choose General > About.

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmqoYrkACgkQ4Ifiq8DH
7PWrzxAArZLZNtxDt3ahEmixhX218MjL/f/tG1WlZ/zhH1dXjKfleeuEUo+SQPr9
il6kMyNj7C83XSiAOQbDEUc8CNBFGa9Rria1vyQbzsi1bMPHU7YswicMhaYoQdgQ
H3qupQqzsWhkK8jH0q26FAs2ZmBWRcxCkJ/kCc6YIw/mc3QwgMccuu88N59LL3qu
YHz2oWZHunEzoA5x4xyLqali0zKQBJ3j1+wWBPijj0DqX2I23c8Vu+4CM5RoDsNL
R0ca8DKY7y5t4OxemJTDNVpkN13mTT7cz6fw4Wg7Ob1M0ebgULx+OWh7NDQI4VUJ
Tu1iz8R53sljSt6GofLrxSJ+A3torHgD3PdorfACc95zmIddPky8RHmu21DQDRz+
IP36NXtVZbCwpE4FLzP9P/B9nrFEWViVFMk6BM6rwpXTuOBKpLMvKEoE4FiFW5Wf
XXO7YsKyIxQ72CEFV35FNlkHUTenKZ53cXgAuXqxyROG5+rnpRhMiiRjCQT/NYJ6
unHUyyNRn0BDUOcqZai8l+p/X7yTn6HLLdThu0AqGeWvBpVDuT0bT2PNhuT0CRNv
8AktDLD+OqgUchEVidaNnoGXgTVNpHzg4FWHpyTik7wMJP98J8fxA74vfotpkMYT
Ohyt7ZrbflO/WOmCqNxRrCcSWyfSB1pr8/0dsBzgxa89k7TyD6o=
=Tlee
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • APPLE-SA-09-14-2026-8 visionOS 27 Apple Product Security via Fulldisclosure (Sep 22)

文章来源: https://seclists.org/fulldisclosure/2026/Sep/60
如有侵权请联系:admin#unsafe.sh