APPLE-SA-09-14-2026-6 tvOS 27
Full Disclosuremailing list archivesFrom: Apple Product Security via Fulldisclos 2026-9-22 18:31:29 Author: seclists.org(查看原文) 阅读量:4 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 14 Sep 2026 15:08:11 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-09-14-2026-6 tvOS 27

tvOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149036.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted image may lead to unexpected
process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-86882: Peter Malone

Accessibility
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved data protection.
CVE-2026-43664: Stuart Wallace, Ilya Andr (andrd3v), Rosyna Keller of
Totally Not Malicious Software, CJ Vana, David Strnadel, Daniel Febrero,
Asaf Cohen, Gongyu Ma (@Mezone0), Jian Lee (@speedyfriend433)

APFS
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84523: Cem Onat Karagun, an anonymous researcher

App Store
Available for: Apple TV 4K 2nd generation and later
Impact: A local app may be able to read a persistent account identifier
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86888: Zhongcheng Li (CK01)

AppleAVD
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-65407: Franco Belman at Blackwing Intelligence

Audio
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to leak sensitive user information
Description: A logic issue was addressed with improved checks.
CVE-2026-65339: Mustafa Calap (@ordinal0, dbg.re), Meta Red Team X - Nik
Tsytsarkin

AuthKit
Available for: Apple TV 4K 2nd generation and later
Impact: A local app may be able to read a persistent account identifier
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84583: Zhongcheng Li from IES Red Team

AVEVideoEncoder
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved checks.
CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic
Research

AVEVideoEncoder
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-84616: Peter Malone

AVEVideoEncoder
Available for: Apple TV 4K 2nd generation and later
Impact: A sandboxed app may be able to execute arbitrary code with
kernel privileges
Description: A race condition was addressed with improved state
management.
CVE-2026-84607: Ruslan Dautov

BackgroundAssets
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved validation.
CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security

Bluetooth
Available for: Apple TV 4K 2nd generation and later
Impact: A remote attacker may be able to cause unexpected app
termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65414

Bluetooth
Available for: Apple TV 4K 2nd generation and later
Impact: An app may gain unauthorized access to Bluetooth
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84560: an anonymous researcher

CloudKit
Available for: Apple TV 4K 2nd generation and later
Impact: A local app may be able to read a persistent account identifier
Description: An information disclosure issue was addressed with improved
state management.
CVE-2026-86895: Stanislav Jelezoglo

CloudKit
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to read device name
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86893: Heiner Gerdes

CoreMedia
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted video file may lead to
unexpected app termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65344: Siyeong kim

CoreMotion
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access motion data from headphones without
user consent
Description: An authorization issue was addressed with improved
validation.
CVE-2026-43737: Stuart Wallace

CoreText
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84596: ret2happy, Meta Product Security

CoreUI
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re)

CoreUI
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted image may lead to unexpected
app termination
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-84571: stratan (@5tratan), Peter Malone

CoreUI
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted asset catalog may lead to
unexpected process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84511: Rahul Raj, stratan (@5tratan)

DeviceCheck
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to read persistent device identifiers
Description: An authorization issue was addressed with improved access
control.
CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill
(@[email protected])

File Bookmark
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to modify a file it only had permission to
read
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-43785: Junyeong Lee (jylab.github.io), Merrick Hare, Aditya
Kumar, John Nzyuko Uvyu, Narendra Singh (@_3P1C)

FontParser
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted font file may lead to
unexpected app termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84524: an anonymous researcher

FontParser
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-84597: Nik Tsytsarkin

Foundation
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause a denial of service
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and
Anthropic Research

Graphics
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg),
Jiyong Yang

Heimdal
Available for: Apple TV 4K 2nd generation and later
Impact: An attacker in a privileged network position may be able to
modify network traffic
Description: A cryptographic issue was addressed with improved integrity
checks.
CVE-2026-84533: Vishal Patidar, Roman Zabicki

ImageIO
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted image may result in disclosure
of process memory
Description: An uninitialized memory issue was addressed with improved
memory initialization.
CVE-2026-84564: Justin O'Leary

ImageIO
Available for: Apple TV 4K 2nd generation and later
Impact: Processing an image may lead to a denial-of-service
Description: The issue was addressed with improved checks.
CVE-2026-65347: Geonha Lee (@leegn4a)

ImageIO
Available for: Apple TV 4K 2nd generation and later
Impact: Processing an image may lead to arbitrary code execution
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-65346: Meta Red Team X - Nik Tsytsarkin

ImageIO
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted image may result in memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan

IOKit
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영

IOMobileFrameBuffer
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
CVE-2026-65398: Chris Bailey - Short Circuit, Mustafa Calap (@ordinal0,
dbg.re), David Strnadel, Meta Red Team X - Nik Tsytsarkin
CVE-2026-64736: Ruslan Dautov, hxr1

IOSurfaceAccelerator
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to leak sensitive kernel state
Description: An information leakage was addressed with additional
validation.
CVE-2026-64760: an anonymous researcher, Seiji Sakurai (@HeapSmasher),
Franco Belman at Blackwing Intelligence

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-28968: genter0, Svetoslav Stolarov & Aisa Fox, Josh Maine of
Calif.io, Dun

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: A local user may be able to cause unexpected system termination
or read kernel memory
Description: A race condition was addressed with additional validation.
CVE-2026-65415: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Ryan Hileman via Xint Code (xint.io)

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: A remote attacker may be able to cause unexpected system
termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-65343: Drinor Selmanaj (Sentry), Surya Narayan Kushwaha

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination or
read kernel memory
Description: An out-of-bounds read was addressed with improved input
validation.
CVE-2026-65349: an anonymous researcher

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A double free issue was addressed with improved memory
management.
CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security
CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2026-65377: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Ye Zhang (@VAR10CK) of Baidu Security

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app with root privileges may be able to read uninitialized
kernel memory
Description: A memory initialization issue was addressed with improved
memory handling.
CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.)

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: Connecting to a malicious NFS server may disclose kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43687: R4mbb of KRsecurity, Peter Malone

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: Connecting to a malicious NFS server may lead to kernel memory
corruption
Description: A use-after-free issue was addressed with improved memory
management.
CVE-2026-43686: Peter Malone

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to determine kernel memory layout
Description: A memory initialization issue was addressed with improved
memory handling.
CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to disclose kernel memory
Description: An information disclosure issue was addressed with improved
memory management.
CVE-2026-84530: Vladislav Shevchenko (Positive Technologies)

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong
and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: A local user may be able to cause unexpected system termination
or read kernel memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A race condition was addressed with improved state
handling.
CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to disclose kernel memory
Description: An out-of-bounds read was addressed with improved input
validation.
CVE-2026-86903: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-65330: Ashish Kunwar, Mikhail Lozhnikov of Positive
Technologies, Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan
Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-28935: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to cause unexpected system termination
Description: A type confusion issue was addressed with improved checks.
CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

MediaRemote
Available for: Apple TV 4K 2nd generation and later
Impact: A sandboxed app may be able to access the System Keychain
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84628: Myeonghun Pak, Nathaniel Oh (@calysteon), Alan Banderas
(@creeper4004)

Model I/O
Available for: Apple TV 4K 2nd generation and later
Impact: Opening a maliciously crafted file may lead to unexpected
process termination
Description: A buffer overflow was addressed with improved size
validation.
CVE-2026-84497: Yiğit Can YILMAZ (@yilmazcanyigit)

Music
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84615: Stanislav Jelezoglo

NetworkExtension
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos

NetworkExtension
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to identify what other apps a user has
installed
Description: An information disclosure issue was addressed with improved
state management.
CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team

Photos Storage
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84491: an anonymous researcher

Photos Storage
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-84629: Stanislav Jelezoglo

RealityKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-28966: stratan (@5tratan)

RealityKit
Available for: Apple TV 4K 2nd generation and later
Impact: Opening a maliciously crafted file may cause unexpected process
termination or disclose process memory
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-84532: Hongsik Kim (mnur), stratan (@5tratan)

SceneKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted file may result in disclosure
of process memory
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84487: stratan (@5tratan), Dhiyanesh Selvaraj (@redroot97),
Peter Malone

SceneKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: The issue was addressed with improved memory handling.
CVE-2026-84632: Peter Malone

SceneKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84620: Peter Malone

SceneKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter
Malone
CVE-2026-84611: Nathaniel Oh (@calysteon)

SceneKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted 3D scene may lead to unexpected
process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84526: stratan (@5tratan)

Security
Available for: Apple TV 4K 2nd generation and later
Impact: An attacker with a compromised intermediate certificate
authority may be able to issue certificates with arbitrary extended key
usages
Description: A certificate validation issue was addressed with improved
certificate validation.
CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier,
Filip Olszak

Shortcuts
Available for: Apple TV 4K 2nd generation and later
Impact: A malicious shortcut may be able to send messages without user
confirmation
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84600: Owen Pawling (@owenpawling)

Siri
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86884: Stanislav Jelezoglo, Gongyu Ma (twitter @Mezone0)

Software Update
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to modify protected system files
Description: A permissions issue was addressed with improved path
validation.
CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team

Symptom Framework
Available for: Apple TV 4K 2nd generation and later
Impact: A malicious application may be able to determine a user's
current location
Description: A privacy issue was addressed with improved private data
redaction for log entries.
CVE-2026-84513: Sindre Sorhus

TCC
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom

WebKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process termination
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 310457
CVE-2026-84635: Souta Sugiyama

WebKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 318405
CVE-2026-65341: Henock Habte

WebKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A permissions issue was addressed by removing the
vulnerable code.
WebKit Bugzilla: 315121
CVE-2026-64753: Viggo Lekdorf

WebKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 316347
CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative

WebKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process termination
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313703
CVE-2026-64787: 杉山 壮太, Shubham Chaskar

WebKit
Available for: Apple TV 4K 2nd generation and later
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: A memory corruption issue was addressed with improved
memory handling.
WebKit Bugzilla: 317317
CVE-2026-43794: Dung Do (@_piers2) of Calif.io

WebKit History
Available for: Apple TV 4K 2nd generation and later
Impact: Visiting a maliciously crafted website may leak sensitive data
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 322124
CVE-2026-64778: Mohit Negi

WebRTC
Available for: Apple TV 4K 2nd generation and later
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
WebKit Bugzilla: 322761
CVE-2026-65391: Myungyong Lee

WebRTC
Available for: Apple TV 4K 2nd generation and later
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-65390: Kwak Kiyong (@Pwnkai23), Song Nuri

Wi-Fi Connectivity
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84636: Jian Lee (@speedyfriend433)

XPC
Available for: Apple TV 4K 2nd generation and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84617: Stuart Wallace

Additional recognition

Accounts
We would like to acknowledge Wojciech Regula of SecuRing
(wojciechregula.blog) for their assistance.

AppleKeyStore
We would like to acknowledge Abdurrahman Nafi, Francisco Knabe, Karol
Mazurek (@Karmaz95) of AFINE, Somair Ansar, YOKI, an anonymous
researcher, 晓娟 谢 for their assistance.

AVEVideoEncoder
We would like to acknowledge tamdao for their assistance.

Bluetooth
We would like to acknowledge Suresh Sundaram for their assistance.

CloudKit
We would like to acknowledge Hikerell (Loadshine Lab) for their
assistance.

Compression
We would like to acknowledge Tommy DeVoss from Braze Security Team
(@thedawgyg) for their assistance.

CoreAudio
We would like to acknowledge Patrick Saif / x.com/weezerOSINT /
github.com/sai2fast for their assistance.

CoreBluetooth - LE
We would like to acknowledge Ashmit Sharma & Atul RV, Dun, Maliq
Barnard, Nicholas C. of Onymos Inc. (onymos.com), Peter Malone, Robert M
for their assistance.

CoreGraphics
We would like to acknowledge Gandalf4a of PKU-Changsha Institute for
Computing and Digital Economy for their assistance.

CoreMedia
We would like to acknowledge Chris Bailey - Short Circuit for their
assistance.

CoreUI
We would like to acknowledge Peter Malone for their assistance.

DataAccess
We would like to acknowledge Adetayo Adebimpe (Cyboghostginx) for their
assistance.

iCloud
We would like to acknowledge 3ndy1(@_3ndy1) and moyu for their
assistance.

ImageIO
We would like to acknowledge Muhamad Syaiful, an anonymous researcher,
songbird for their assistance.

IOMobileFrameBuffer
We would like to acknowledge Iain Harkiss, Jian Lee (@speedyfriend433)
for their assistance.

IOSurfaceAccelerator
We would like to acknowledge Chanwit Muenprakoddee (ChemIndy), Franco
Belman at Blackwing Intelligence, Iain Harkiss, an anonymous researcher,
beist, hxr1 for their assistance.

Kernel
We would like to acknowledge Bhaswanth Chigurupati, Billy Jheng Bing
Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Cem
Onat Karagun, James Duffy (@0x4A616D657344), Lyutoon, N.M.Praveen
Nawarathne (@zblockrat), Nebula Security (@nebusecurity), Peter Malone,
Redon Gashi of Sentry, Robert Tran, Xiang Li from AOSP Lab @Nankai
University, an anonymous researcher for their assistance.

mDNSResponder
We would like to acknowledge Issa Sancho, Jian Zhou for their
assistance.

Pro Res
We would like to acknowledge Meta Red Team X - Nik Tsytsarkin for their
assistance.

Remote Control
We would like to acknowledge Ruslan Dautov for their assistance.

RemoteServiceDiscovery
We would like to acknowledge Tristan Madani (@TristanInSec) from Talence
Security, an anonymous researcher for their assistance.

Security
We would like to acknowledge John Lussier, Masahiro Kawada (@kawakatz),
Roman Zabicki for their assistance.

VoiceOver
We would like to acknowledge Hariji Vivek Pandey for their assistance.

WebKit
We would like to acknowledge @TristanInSec, Henock Habte, Kenneth Hsu,
Maher Azzouzi, Meridian Miftari, OpenAI Codex Security - Amy Burnett, an
anonymous researcher, ret2happy, wwwlk for their assistance.

WebKit Canvas
We would like to acknowledge Utkarsh Pal for their assistance.

Wi-Fi
We would like to acknowledge E Vestavik (@Dynasty) for their assistance.

Apple TV will periodically check for software updates. Alternatively,
you may manually check for software updates by selecting "Settings ->
System -> Software Update -> Update Software."

To check the current version of software, select "Settings -> General ->
About."

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmqoYo0ACgkQ4Ifiq8DH
7PUjKQ/+MxOh+MYtPvUm4NRiAxVQKHesXx1zyKhIQafgOL4CjhYQWBrvnge/vqXs
/Yrq9pnd1I6MNVp/shVKS3nIAfwBNASq9G2pj2X7jGbh8n53fHtcvD85fkCKPLbG
rIP8AHgdSzc6trAU6j7zqeS693zl5bjQo+TGw67IcTHO0y6j2GMOlSUzYp0eHywC
u4x2MFkTgHtjOiKRIWU58JRDCiVw5s+0Xz3CHV//TjhEUj3fsnf9DlbrHAO8i3mA
gBLMXV5VWzfUN8udwODvQsNKS2fZ2Zi/GD9MYr34ybLwEC0sAxPf61H1fYbyqaiY
spnEumRLLUhQasBP0FJ8+MilkdKe1daykoFn3wqkjuyyUcaz2s8HZiQtX/YC1qlL
m1PX9XStMVjm2n9o45976wNCJHnV3wX5htUGo/3Hgus07cGyUJl94kd/aip7iLrP
GsJoO5Ul3amOxsHkJzLSyOp4G87t3Iq2i1JB/GtCK46XRIfktHFDanFzdslqd4qE
nOJg0bMtyuNikKKhLa64Et14e6HNKn+eA1pQ0FWMTflAQCToFVDJWHMk6JqYucB/
XCuNMPxne/SZ40bbJVOZgQQGs/PYLNHIGOpof1epoq7g9v+x7J6GKciUXh0eMSVx
vAuotYDdAFZRsOWc/jlh0xYhXDDBxt/d3MCj7Uzx2EgacOdZ+eQ=
=N6QM
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • APPLE-SA-09-14-2026-6 tvOS 27 Apple Product Security via Fulldisclosure (Sep 22)

文章来源: https://seclists.org/fulldisclosure/2026/Sep/58
如有侵权请联系:admin#unsafe.sh