Full Disclosure mailing list archives
APPLE-SA-09-14-2026-6 tvOS 27
From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 14 Sep 2026 15:08:11 -0700
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-09-14-2026-6 tvOS 27 tvOS 27 addresses the following issues. Information about the security content is also available at https://support.apple.com/149036. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Accelerate Framework Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted image may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-86882: Peter Malone Accessibility Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved data protection. CVE-2026-43664: Stuart Wallace, Ilya Andr (andrd3v), Rosyna Keller of Totally Not Malicious Software, CJ Vana, David Strnadel, Daniel Febrero, Asaf Cohen, Gongyu Ma (@Mezone0), Jian Lee (@speedyfriend433) APFS Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination or write kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84523: Cem Onat Karagun, an anonymous researcher App Store Available for: Apple TV 4K 2nd generation and later Impact: A local app may be able to read a persistent account identifier Description: A permissions issue was addressed with additional restrictions. CVE-2026-86888: Zhongcheng Li (CK01) AppleAVD Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65407: Franco Belman at Blackwing Intelligence Audio Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to leak sensitive user information Description: A logic issue was addressed with improved checks. CVE-2026-65339: Mustafa Calap (@ordinal0, dbg.re), Meta Red Team X - Nik Tsytsarkin AuthKit Available for: Apple TV 4K 2nd generation and later Impact: A local app may be able to read a persistent account identifier Description: A permissions issue was addressed with additional restrictions. CVE-2026-84583: Zhongcheng Li from IES Red Team AVEVideoEncoder Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination Description: The issue was addressed with improved checks. CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic Research AVEVideoEncoder Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination Description: A type confusion issue was addressed with improved memory handling. CVE-2026-84616: Peter Malone AVEVideoEncoder Available for: Apple TV 4K 2nd generation and later Impact: A sandboxed app may be able to execute arbitrary code with kernel privileges Description: A race condition was addressed with improved state management. CVE-2026-84607: Ruslan Dautov BackgroundAssets Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access sensitive user data Description: A logic issue was addressed with improved validation. CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security Bluetooth Available for: Apple TV 4K 2nd generation and later Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65414 Bluetooth Available for: Apple TV 4K 2nd generation and later Impact: An app may gain unauthorized access to Bluetooth Description: An authorization issue was addressed with improved state management. CVE-2026-84560: an anonymous researcher CloudKit Available for: Apple TV 4K 2nd generation and later Impact: A local app may be able to read a persistent account identifier Description: An information disclosure issue was addressed with improved state management. CVE-2026-86895: Stanislav Jelezoglo CloudKit Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to read device name Description: A permissions issue was addressed with additional restrictions. CVE-2026-86893: Heiner Gerdes CoreMedia Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted video file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65344: Siyeong kim CoreMotion Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access motion data from headphones without user consent Description: An authorization issue was addressed with improved validation. CVE-2026-43737: Stuart Wallace CoreText Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84596: ret2happy, Meta Product Security CoreUI Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re) CoreUI Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted image may lead to unexpected app termination Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-84571: stratan (@5tratan), Peter Malone CoreUI Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted asset catalog may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84511: Rahul Raj, stratan (@5tratan) DeviceCheck Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to read persistent device identifiers Description: An authorization issue was addressed with improved access control. CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill (@jjtech@infosec.exchange) File Bookmark Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to modify a file it only had permission to read Description: A permissions issue was addressed with additional restrictions. CVE-2026-43785: Junyeong Lee (jylab.github.io), Merrick Hare, Aditya Kumar, John Nzyuko Uvyu, Narendra Singh (@_3P1C) FontParser Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted font file may lead to unexpected app termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84524: an anonymous researcher FontParser Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read issue was addressed with improved input validation. CVE-2026-84597: Nik Tsytsarkin Foundation Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause a denial of service Description: A type confusion issue was addressed with improved memory handling. CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research Graphics Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with improved state handling. CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg), Jiyong Yang Heimdal Available for: Apple TV 4K 2nd generation and later Impact: An attacker in a privileged network position may be able to modify network traffic Description: A cryptographic issue was addressed with improved integrity checks. CVE-2026-84533: Vishal Patidar, Roman Zabicki ImageIO Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted image may result in disclosure of process memory Description: An uninitialized memory issue was addressed with improved memory initialization. CVE-2026-84564: Justin O'Leary ImageIO Available for: Apple TV 4K 2nd generation and later Impact: Processing an image may lead to a denial-of-service Description: The issue was addressed with improved checks. CVE-2026-65347: Geonha Lee (@leegn4a) ImageIO Available for: Apple TV 4K 2nd generation and later Impact: Processing an image may lead to arbitrary code execution Description: An integer overflow was addressed with improved input validation. CVE-2026-65346: Meta Red Team X - Nik Tsytsarkin ImageIO Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted image may result in memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan IOKit Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영 IOMobileFrameBuffer Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds access issue was addressed with improved bounds checking. CVE-2026-65398: Chris Bailey - Short Circuit, Mustafa Calap (@ordinal0, dbg.re), David Strnadel, Meta Red Team X - Nik Tsytsarkin CVE-2026-64736: Ruslan Dautov, hxr1 IOSurfaceAccelerator Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to leak sensitive kernel state Description: An information leakage was addressed with additional validation. CVE-2026-64760: an anonymous researcher, Seiji Sakurai (@HeapSmasher), Franco Belman at Blackwing Intelligence Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-28968: genter0, Svetoslav Stolarov & Aisa Fox, Josh Maine of Calif.io, Dun Kernel Available for: Apple TV 4K 2nd generation and later Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: A race condition was addressed with additional validation. CVE-2026-65415: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ryan Hileman via Xint Code (xint.io) Kernel Available for: Apple TV 4K 2nd generation and later Impact: A remote attacker may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65343: Drinor Selmanaj (Sentry), Surya Narayan Kushwaha Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved input validation. CVE-2026-65349: an anonymous researcher Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A double free issue was addressed with improved memory management. CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with improved state handling. CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination Description: A memory corruption issue was addressed with improved memory handling. CVE-2026-65377: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ye Zhang (@VAR10CK) of Baidu Security Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app with root privileges may be able to read uninitialized kernel memory Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.) Kernel Available for: Apple TV 4K 2nd generation and later Impact: Connecting to a malicious NFS server may disclose kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-43687: R4mbb of KRsecurity, Peter Malone Kernel Available for: Apple TV 4K 2nd generation and later Impact: Connecting to a malicious NFS server may lead to kernel memory corruption Description: A use-after-free issue was addressed with improved memory management. CVE-2026-43686: Peter Malone Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to determine kernel memory layout Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to disclose kernel memory Description: An information disclosure issue was addressed with improved memory management. CVE-2026-84530: Vladislav Shevchenko (Positive Technologies) Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple TV 4K 2nd generation and later Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A race condition was addressed with improved state handling. CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to disclose kernel memory Description: An out-of-bounds read was addressed with improved input validation. CVE-2026-86903: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-65330: Ashish Kunwar, Mikhail Lozhnikov of Positive Technologies, Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-28935: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to cause unexpected system termination Description: A type confusion issue was addressed with improved checks. CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. MediaRemote Available for: Apple TV 4K 2nd generation and later Impact: A sandboxed app may be able to access the System Keychain Description: An authorization issue was addressed with improved state management. CVE-2026-84628: Myeonghun Pak, Nathaniel Oh (@calysteon), Alan Banderas (@creeper4004) Model I/O Available for: Apple TV 4K 2nd generation and later Impact: Opening a maliciously crafted file may lead to unexpected process termination Description: A buffer overflow was addressed with improved size validation. CVE-2026-84497: Yiğit Can YILMAZ (@yilmazcanyigit) Music Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-84615: Stanislav Jelezoglo NetworkExtension Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos NetworkExtension Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to identify what other apps a user has installed Description: An information disclosure issue was addressed with improved state management. CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team Photos Storage Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions. CVE-2026-84491: an anonymous researcher Photos Storage Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to fingerprint the user Description: This issue was addressed with additional entitlement checks. CVE-2026-84629: Stanislav Jelezoglo RealityKit Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-28966: stratan (@5tratan) RealityKit Available for: Apple TV 4K 2nd generation and later Impact: Opening a maliciously crafted file may cause unexpected process termination or disclose process memory Description: An out-of-bounds read issue was addressed with improved input validation. CVE-2026-84532: Hongsik Kim (mnur), stratan (@5tratan) SceneKit Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted file may result in disclosure of process memory Description: An integer overflow was addressed with improved input validation. CVE-2026-84487: stratan (@5tratan), Dhiyanesh Selvaraj (@redroot97), Peter Malone SceneKit Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: The issue was addressed with improved memory handling. CVE-2026-84632: Peter Malone SceneKit Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: An integer overflow was addressed with improved input validation. CVE-2026-84620: Peter Malone SceneKit Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter Malone CVE-2026-84611: Nathaniel Oh (@calysteon) SceneKit Available for: Apple TV 4K 2nd generation and later Impact: Processing a maliciously crafted 3D scene may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84526: stratan (@5tratan) Security Available for: Apple TV 4K 2nd generation and later Impact: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages Description: A certificate validation issue was addressed with improved certificate validation. CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier, Filip Olszak Shortcuts Available for: Apple TV 4K 2nd generation and later Impact: A malicious shortcut may be able to send messages without user confirmation Description: An authorization issue was addressed with improved state management. CVE-2026-84600: Owen Pawling (@owenpawling) Siri Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions. CVE-2026-86884: Stanislav Jelezoglo, Gongyu Ma (twitter @Mezone0) Software Update Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to modify protected system files Description: A permissions issue was addressed with improved path validation. CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team Symptom Framework Available for: Apple TV 4K 2nd generation and later Impact: A malicious application may be able to determine a user's current location Description: A privacy issue was addressed with improved private data redaction for log entries. CVE-2026-84513: Sindre Sorhus TCC Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access sensitive user data Description: A logging issue was addressed with improved data redaction. CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom WebKit Available for: Apple TV 4K 2nd generation and later Impact: Processing maliciously crafted web content may lead to an unexpected process termination Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 310457 CVE-2026-84635: Souta Sugiyama WebKit Available for: Apple TV 4K 2nd generation and later Impact: Processing maliciously crafted web content may lead to memory corruption Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 318405 CVE-2026-65341: Henock Habte WebKit Available for: Apple TV 4K 2nd generation and later Impact: Processing maliciously crafted web content may disclose sensitive user information Description: A permissions issue was addressed by removing the vulnerable code. WebKit Bugzilla: 315121 CVE-2026-64753: Viggo Lekdorf WebKit Available for: Apple TV 4K 2nd generation and later Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 316347 CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative WebKit Available for: Apple TV 4K 2nd generation and later Impact: Processing maliciously crafted web content may lead to an unexpected process termination Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 313703 CVE-2026-64787: 杉山 壮太, Shubham Chaskar WebKit Available for: Apple TV 4K 2nd generation and later Impact: Processing maliciously crafted web content may lead to memory corruption Description: A memory corruption issue was addressed with improved memory handling. WebKit Bugzilla: 317317 CVE-2026-43794: Dung Do (@_piers2) of Calif.io WebKit History Available for: Apple TV 4K 2nd generation and later Impact: Visiting a maliciously crafted website may leak sensitive data Description: The issue was addressed with improved checks. WebKit Bugzilla: 322124 CVE-2026-64778: Mohit Negi WebRTC Available for: Apple TV 4K 2nd generation and later Impact: Processing maliciously crafted web content may lead to memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. WebKit Bugzilla: 322761 CVE-2026-65391: Myungyong Lee WebRTC Available for: Apple TV 4K 2nd generation and later Impact: Processing maliciously crafted web content may lead to memory corruption Description: An integer overflow was addressed with improved input validation. CVE-2026-65390: Kwak Kiyong (@Pwnkai23), Song Nuri Wi-Fi Connectivity Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-84636: Jian Lee (@speedyfriend433) XPC Available for: Apple TV 4K 2nd generation and later Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-84617: Stuart Wallace Additional recognition Accounts We would like to acknowledge Wojciech Regula of SecuRing (wojciechregula.blog) for their assistance. AppleKeyStore We would like to acknowledge Abdurrahman Nafi, Francisco Knabe, Karol Mazurek (@Karmaz95) of AFINE, Somair Ansar, YOKI, an anonymous researcher, 晓娟 谢 for their assistance. AVEVideoEncoder We would like to acknowledge tamdao for their assistance. Bluetooth We would like to acknowledge Suresh Sundaram for their assistance. CloudKit We would like to acknowledge Hikerell (Loadshine Lab) for their assistance. Compression We would like to acknowledge Tommy DeVoss from Braze Security Team (@thedawgyg) for their assistance. CoreAudio We would like to acknowledge Patrick Saif / x.com/weezerOSINT / github.com/sai2fast for their assistance. CoreBluetooth - LE We would like to acknowledge Ashmit Sharma & Atul RV, Dun, Maliq Barnard, Nicholas C. of Onymos Inc. (onymos.com), Peter Malone, Robert M for their assistance. CoreGraphics We would like to acknowledge Gandalf4a of PKU-Changsha Institute for Computing and Digital Economy for their assistance. CoreMedia We would like to acknowledge Chris Bailey - Short Circuit for their assistance. CoreUI We would like to acknowledge Peter Malone for their assistance. DataAccess We would like to acknowledge Adetayo Adebimpe (Cyboghostginx) for their assistance. iCloud We would like to acknowledge 3ndy1(@_3ndy1) and moyu for their assistance. ImageIO We would like to acknowledge Muhamad Syaiful, an anonymous researcher, songbird for their assistance. IOMobileFrameBuffer We would like to acknowledge Iain Harkiss, Jian Lee (@speedyfriend433) for their assistance. IOSurfaceAccelerator We would like to acknowledge Chanwit Muenprakoddee (ChemIndy), Franco Belman at Blackwing Intelligence, Iain Harkiss, an anonymous researcher, beist, hxr1 for their assistance. Kernel We would like to acknowledge Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Cem Onat Karagun, James Duffy (@0x4A616D657344), Lyutoon, N.M.Praveen Nawarathne (@zblockrat), Nebula Security (@nebusecurity), Peter Malone, Redon Gashi of Sentry, Robert Tran, Xiang Li from AOSP Lab @Nankai University, an anonymous researcher for their assistance. mDNSResponder We would like to acknowledge Issa Sancho, Jian Zhou for their assistance. Pro Res We would like to acknowledge Meta Red Team X - Nik Tsytsarkin for their assistance. Remote Control We would like to acknowledge Ruslan Dautov for their assistance. RemoteServiceDiscovery We would like to acknowledge Tristan Madani (@TristanInSec) from Talence Security, an anonymous researcher for their assistance. Security We would like to acknowledge John Lussier, Masahiro Kawada (@kawakatz), Roman Zabicki for their assistance. VoiceOver We would like to acknowledge Hariji Vivek Pandey for their assistance. WebKit We would like to acknowledge @TristanInSec, Henock Habte, Kenneth Hsu, Maher Azzouzi, Meridian Miftari, OpenAI Codex Security - Amy Burnett, an anonymous researcher, ret2happy, wwwlk for their assistance. WebKit Canvas We would like to acknowledge Utkarsh Pal for their assistance. Wi-Fi We would like to acknowledge E Vestavik (@Dynasty) for their assistance. Apple TV will periodically check for software updates. Alternatively, you may manually check for software updates by selecting "Settings -> System -> Software Update -> Update Software." To check the current version of software, select "Settings -> General -> About." All information is also posted on the Apple Security Releases web site: https://support.apple.com/100100. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmqoYo0ACgkQ4Ifiq8DH 7PUjKQ/+MxOh+MYtPvUm4NRiAxVQKHesXx1zyKhIQafgOL4CjhYQWBrvnge/vqXs /Yrq9pnd1I6MNVp/shVKS3nIAfwBNASq9G2pj2X7jGbh8n53fHtcvD85fkCKPLbG rIP8AHgdSzc6trAU6j7zqeS693zl5bjQo+TGw67IcTHO0y6j2GMOlSUzYp0eHywC u4x2MFkTgHtjOiKRIWU58JRDCiVw5s+0Xz3CHV//TjhEUj3fsnf9DlbrHAO8i3mA gBLMXV5VWzfUN8udwODvQsNKS2fZ2Zi/GD9MYr34ybLwEC0sAxPf61H1fYbyqaiY spnEumRLLUhQasBP0FJ8+MilkdKe1daykoFn3wqkjuyyUcaz2s8HZiQtX/YC1qlL m1PX9XStMVjm2n9o45976wNCJHnV3wX5htUGo/3Hgus07cGyUJl94kd/aip7iLrP GsJoO5Ul3amOxsHkJzLSyOp4G87t3Iq2i1JB/GtCK46XRIfktHFDanFzdslqd4qE nOJg0bMtyuNikKKhLa64Et14e6HNKn+eA1pQ0FWMTflAQCToFVDJWHMk6JqYucB/ XCuNMPxne/SZ40bbJVOZgQQGs/PYLNHIGOpof1epoq7g9v+x7J6GKciUXh0eMSVx vAuotYDdAFZRsOWc/jlh0xYhXDDBxt/d3MCj7Uzx2EgacOdZ+eQ= =N6QM -----END PGP SIGNATURE----- _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- APPLE-SA-09-14-2026-6 tvOS 27 Apple Product Security via Fulldisclosure (Sep 22)
