Full Disclosure mailing list archives
APPLE-SA-09-14-2026-7 watchOS 27
From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 14 Sep 2026 15:09:02 -0700
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-09-14-2026-7 watchOS 27 watchOS 27 addresses the following issues. Information about the security content is also available at https://support.apple.com/149037. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Accelerate Framework Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted image may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-86882: Peter Malone Accessibility Available for: Apple Watch Series 9 and later Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved data protection. CVE-2026-43664: Stuart Wallace, Ilya Andr (andrd3v), Rosyna Keller of Totally Not Malicious Software, CJ Vana, David Strnadel, Daniel Febrero, Asaf Cohen, Gongyu Ma (@Mezone0), Jian Lee (@speedyfriend433) APFS Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination or write kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84523: Cem Onat Karagun, an anonymous researcher App Store Available for: Apple Watch Series 9 and later Impact: A local app may be able to read a persistent account identifier Description: A permissions issue was addressed with additional restrictions. CVE-2026-86888: Zhongcheng Li (CK01) Apple Account Available for: Apple Watch Series 9 and later Impact: A malicious application may be able to leak sensitive user information Description: An information disclosure issue was addressed with improved state management. CVE-2026-84586: Prashan Samarathunge, Zhongcheng Li (CK01) AppleAVD Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65407: Franco Belman at Blackwing Intelligence Audio Available for: Apple Watch Series 9 and later Impact: An app may be able to leak sensitive user information Description: A logic issue was addressed with improved checks. CVE-2026-65339: Mustafa Calap (@ordinal0, dbg.re), Meta Red Team X - Nik Tsytsarkin AuthKit Available for: Apple Watch Series 9 and later Impact: A local app may be able to read a persistent account identifier Description: A permissions issue was addressed with additional restrictions. CVE-2026-84583: Zhongcheng Li from IES Red Team AVEVideoEncoder Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination Description: The issue was addressed with improved checks. CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic Research AVEVideoEncoder Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination Description: A type confusion issue was addressed with improved memory handling. CVE-2026-84616: Peter Malone AVEVideoEncoder Available for: Apple Watch Series 9 and later Impact: A sandboxed app may be able to execute arbitrary code with kernel privileges Description: A race condition was addressed with improved state management. CVE-2026-84607: Ruslan Dautov Bluetooth Available for: Apple Watch Series 9 and later Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65414 Bluetooth Available for: Apple Watch Series 9 and later Impact: An app may gain unauthorized access to Bluetooth Description: An authorization issue was addressed with improved state management. CVE-2026-84560: an anonymous researcher CloudKit Available for: Apple Watch Series 9 and later Impact: A local app may be able to read a persistent account identifier Description: An information disclosure issue was addressed with improved state management. CVE-2026-86895: Stanislav Jelezoglo CloudKit Available for: Apple Watch Series 9 and later Impact: An app may be able to read device name Description: A permissions issue was addressed with additional restrictions. CVE-2026-86893: Heiner Gerdes copyfile Available for: Apple Watch Series 9 and later Impact: An archive may be able to bypass Gatekeeper Description: A file quarantine bypass was addressed with additional checks. CVE-2026-65399: Rishabh Jain (rjcyber) of cyberplanet, Pasquale Scola, an anonymous researcher Core Bluetooth Available for: Apple Watch Series 9 and later Impact: An app may be able to access Bluetooth device information Description: An authorization issue was addressed with improved state management. CVE-2026-86891: Dawuge of Shuffle Team CoreMedia Available for: Apple Watch Series 9 and later Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-86876: Chris Bailey - Short Circuit CoreMotion Available for: Apple Watch Series 9 and later Impact: An app may be able to access motion data from headphones without user consent Description: An authorization issue was addressed with improved validation. CVE-2026-43737: Stuart Wallace CoreText Available for: Apple Watch Series 9 and later Impact: Processing web content may lead to a denial-of-service Description: A null pointer dereference was addressed with improved input validation. CVE-2026-65412: Pavan Nallamothu CoreText Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84596: ret2happy, Meta Product Security CoreUI Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re) CoreUI Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted image may lead to unexpected app termination Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-84571: stratan (@5tratan), Peter Malone CoreUI Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted asset catalog may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84511: Rahul Raj, stratan (@5tratan) DeviceCheck Available for: Apple Watch Series 9 and later Impact: An app may be able to read persistent device identifiers Description: An authorization issue was addressed with improved access control. CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill (@jjtech@infosec.exchange) FontParser Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted font file may lead to unexpected app termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84524: an anonymous researcher FontParser Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read issue was addressed with improved input validation. CVE-2026-84597: Nik Tsytsarkin Foundation Available for: Apple Watch Series 9 and later Impact: An app may be able to cause a denial of service Description: A type confusion issue was addressed with improved memory handling. CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research Graphics Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with improved state handling. CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg), Jiyong Yang Heimdal Available for: Apple Watch Series 9 and later Impact: An attacker in a privileged network position may be able to modify network traffic Description: A cryptographic issue was addressed with improved integrity checks. CVE-2026-84533: Vishal Patidar, Roman Zabicki ImageIO Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted image may result in disclosure of process memory Description: An uninitialized memory issue was addressed with improved memory initialization. CVE-2026-84564: Justin O'Leary ImageIO Available for: Apple Watch Series 9 and later Impact: Processing an image may lead to a denial-of-service Description: The issue was addressed with improved checks. CVE-2026-65347: Geonha Lee (@leegn4a) ImageIO Available for: Apple Watch Series 9 and later Impact: Processing an image may lead to arbitrary code execution Description: An integer overflow was addressed with improved input validation. CVE-2026-65346: Meta Red Team X - Nik Tsytsarkin IOGPUFamily Available for: Apple Watch Series 9 and later Impact: Processing maliciously crafted web content may lead to memory corruption Description: The issue was addressed with improved memory handling. CVE-2026-64788: an anonymous researcher, f00l (@PPPF00L) and 3ndy1(@_3ndy1) and Minghao Lin@Y1nkoc and 云散花折, Arjanit Isufi IOKit Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영 IOMobileFrameBuffer Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds access issue was addressed with improved bounds checking. CVE-2026-65398: Chris Bailey - Short Circuit, Mustafa Calap (@ordinal0, dbg.re), David Strnadel, Meta Red Team X - Nik Tsytsarkin CVE-2026-64736: Ruslan Dautov, hxr1 IOSurfaceAccelerator Available for: Apple Watch Series 9 and later Impact: An app may be able to leak sensitive kernel state Description: An information leakage was addressed with additional validation. CVE-2026-64760: an anonymous researcher, Seiji Sakurai (@HeapSmasher), Franco Belman at Blackwing Intelligence Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-28968: genter0, Svetoslav Stolarov & Aisa Fox, Josh Maine of Calif.io, Dun Kernel Available for: Apple Watch Series 9 and later Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: A race condition was addressed with additional validation. CVE-2026-65415: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ryan Hileman via Xint Code (xint.io) Kernel Available for: Apple Watch Series 9 and later Impact: A remote attacker may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65343: Drinor Selmanaj (Sentry), Surya Narayan Kushwaha Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved input validation. CVE-2026-65349: an anonymous researcher Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A double free issue was addressed with improved memory management. CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with improved state handling. CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination Description: A memory corruption issue was addressed with improved memory handling. CVE-2026-65377: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ye Zhang (@VAR10CK) of Baidu Security Kernel Available for: Apple Watch Series 9 and later Impact: An app with root privileges may be able to read uninitialized kernel memory Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.) Kernel Available for: Apple Watch Series 9 and later Impact: Connecting to a malicious NFS server may disclose kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-43687: R4mbb of KRsecurity, Peter Malone Kernel Available for: Apple Watch Series 9 and later Impact: Connecting to a malicious NFS server may lead to kernel memory corruption Description: A use-after-free issue was addressed with improved memory management. CVE-2026-43686: Peter Malone Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to determine kernel memory layout Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to disclose kernel memory Description: An information disclosure issue was addressed with improved memory management. CVE-2026-84530: Vladislav Shevchenko (Positive Technologies) Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Watch Series 9 and later Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A race condition was addressed with improved state handling. CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to disclose kernel memory Description: An out-of-bounds read was addressed with improved input validation. CVE-2026-86903: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-65330: Ashish Kunwar, Mikhail Lozhnikov of Positive Technologies, Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-28935: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Watch Series 9 and later Impact: An app may be able to cause unexpected system termination Description: A type confusion issue was addressed with improved checks. CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. libarchive Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: A heap buffer overflow was addressed with improved bounds checking. CVE-2026-86870: Kitten Food MediaRemote Available for: Apple Watch Series 9 and later Impact: A sandboxed app may be able to access the System Keychain Description: An authorization issue was addressed with improved state management. CVE-2026-84628: Myeonghun Pak, Nathaniel Oh (@calysteon), Alan Banderas (@creeper4004) NetworkExtension Available for: Apple Watch Series 9 and later Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos NetworkExtension Available for: Apple Watch Series 9 and later Impact: An app may be able to identify what other apps a user has installed Description: An information disclosure issue was addressed with improved state management. CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team Photos Storage Available for: Apple Watch Series 9 and later Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions. CVE-2026-84491: an anonymous researcher Photos Storage Available for: Apple Watch Series 9 and later Impact: An app may be able to fingerprint the user Description: This issue was addressed with additional entitlement checks. CVE-2026-84629: Stanislav Jelezoglo Reminders Available for: Apple Watch Series 9 and later Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved checks. CVE-2026-65403: Rahul Raj Sandbox Available for: Apple Watch Series 9 and later Impact: An app may be able to bypass network restrictions Description: A logic issue was addressed with improved validation. CVE-2026-84551: Issa Sancho Sandbox Profiles Available for: Apple Watch Series 9 and later Impact: An app may be able to fingerprint the user Description: A permissions issue was addressed with additional sandbox restrictions. CVE-2026-84625: Ilya Andr (andrd3v) of Positive Technologies, CJ Vana Sandbox Profiles Available for: Apple Watch Series 9 and later Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions. CVE-2026-84603: Gongyu Ma (@Mezone0), CJ Vana, Stanislav Jelezoglo SceneKit Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted file may result in disclosure of process memory Description: An integer overflow was addressed with improved input validation. CVE-2026-84487: stratan (@5tratan), Dhiyanesh Selvaraj (@redroot97), Peter Malone SceneKit Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: The issue was addressed with improved memory handling. CVE-2026-84632: Peter Malone SceneKit Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: An integer overflow was addressed with improved input validation. CVE-2026-84620: Peter Malone SceneKit Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter Malone CVE-2026-84611: Nathaniel Oh (@calysteon) SceneKit Available for: Apple Watch Series 9 and later Impact: Processing a maliciously crafted 3D scene may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84526: stratan (@5tratan) Security Available for: Apple Watch Series 9 and later Impact: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages Description: A certificate validation issue was addressed with improved certificate validation. CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier, Filip Olszak Shortcuts Available for: Apple Watch Series 9 and later Impact: A malicious shortcut may be able to send messages without user confirmation Description: An authorization issue was addressed with improved state management. CVE-2026-84600: Owen Pawling (@owenpawling) Siri Available for: Apple Watch Series 9 and later Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions. CVE-2026-86884: Stanislav Jelezoglo, Gongyu Ma (twitter @Mezone0) Software Update Available for: Apple Watch Series 9 and later Impact: An app may be able to modify protected system files Description: A permissions issue was addressed with improved path validation. CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team Symptom Framework Available for: Apple Watch Series 9 and later Impact: A malicious application may be able to determine a user's current location Description: A privacy issue was addressed with improved private data redaction for log entries. CVE-2026-84513: Sindre Sorhus TCC Available for: Apple Watch Series 9 and later Impact: An app may be able to modify protected system files Description: A path traversal issue was addressed with improved input validation. CVE-2026-86886: Constantin Clerc, Shad J, huami1314 (@huamidev), Huy Nguyen (@34306) of Calif.io, an anonymous researcher TCC Available for: Apple Watch Series 9 and later Impact: An app may be able to access sensitive user data Description: A logging issue was addressed with improved data redaction. CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom Watch App Available for: Apple Watch Series 9 and later Impact: An app may be able to track users across apps and websites without permission Description: A privacy issue was addressed with improved state management. CVE-2026-86904: Stanislav Jelezoglo WebKit Available for: Apple Watch Series 9 and later Impact: Processing maliciously crafted web content may lead to an unexpected process termination Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 310457 CVE-2026-84635: Souta Sugiyama WebKit Available for: Apple Watch Series 9 and later Impact: Processing maliciously crafted web content may lead to memory corruption Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 318405 CVE-2026-65341: Henock Habte WebKit Available for: Apple Watch Series 9 and later Impact: Processing maliciously crafted web content may disclose sensitive user information Description: A permissions issue was addressed by removing the vulnerable code. WebKit Bugzilla: 315121 CVE-2026-64753: Viggo Lekdorf WebKit Available for: Apple Watch Series 9 and later Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 316347 CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative WebKit Available for: Apple Watch Series 9 and later Impact: Processing maliciously crafted web content may lead to an unexpected process termination Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 313703 CVE-2026-64787: 杉山 壮太, Shubham Chaskar WebKit Available for: Apple Watch Series 9 and later Impact: Processing maliciously crafted web content may lead to memory corruption Description: A memory corruption issue was addressed with improved memory handling. WebKit Bugzilla: 317317 CVE-2026-43794: Dung Do (@_piers2) of Calif.io WebKit History Available for: Apple Watch Series 9 and later Impact: Visiting a maliciously crafted website may leak sensitive data Description: The issue was addressed with improved checks. WebKit Bugzilla: 322124 CVE-2026-64778: Mohit Negi WebRTC Available for: Apple Watch Series 9 and later Impact: Processing maliciously crafted web content may lead to memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. WebKit Bugzilla: 322761 CVE-2026-65391: Myungyong Lee WebRTC Available for: Apple Watch Series 9 and later Impact: Processing maliciously crafted web content may lead to memory corruption Description: An integer overflow was addressed with improved input validation. CVE-2026-65390: Kwak Kiyong (@Pwnkai23), Song Nuri Wi-Fi Connectivity Available for: Apple Watch Series 9 and later Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-84636: Jian Lee (@speedyfriend433) Additional recognition Accounts We would like to acknowledge Wojciech Regula of SecuRing (wojciechregula.blog) for their assistance. AppleKeyStore We would like to acknowledge Abdurrahman Nafi, Francisco Knabe, Karol Mazurek (@Karmaz95) of AFINE, Somair Ansar, YOKI, an anonymous researcher, 晓娟 谢 for their assistance. AVEVideoEncoder We would like to acknowledge tamdao for their assistance. Bluetooth We would like to acknowledge Suresh Sundaram for their assistance. Calendar We would like to acknowledge Dany Assuid, Jacob Hazak from Zero-Defense Labs, Varik Matevosyan, stratan (@5tratan) for their assistance. CloudKit We would like to acknowledge Hikerell (Loadshine Lab) for their assistance. Compression We would like to acknowledge Tommy DeVoss from Braze Security Team (@thedawgyg) for their assistance. CoreBluetooth - LE We would like to acknowledge Ashmit Sharma & Atul RV, Dun, Maliq Barnard, Nicholas C. of Onymos Inc. (onymos.com), Peter Malone, Robert M for their assistance. CoreGraphics We would like to acknowledge Gandalf4a of PKU-Changsha Institute for Computing and Digital Economy for their assistance. CoreMedia We would like to acknowledge Chris Bailey - Short Circuit for their assistance. CoreUI We would like to acknowledge Peter Malone for their assistance. DataAccess We would like to acknowledge Adetayo Adebimpe (Cyboghostginx) for their assistance. FaceTime We would like to acknowledge Souhaib Naceri for their assistance. iCloud We would like to acknowledge 3ndy1(@_3ndy1) and moyu for their assistance. ImageIO We would like to acknowledge songbird for their assistance. IOMobileFrameBuffer We would like to acknowledge Iain Harkiss, Jian Lee (@speedyfriend433) for their assistance. IOSurfaceAccelerator We would like to acknowledge Chanwit Muenprakoddee (ChemIndy), Franco Belman at Blackwing Intelligence, Iain Harkiss, an anonymous researcher, beist, hxr1 for their assistance. Kernel We would like to acknowledge Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Cem Onat Karagun, James Duffy (@0x4A616D657344), Lyutoon, N.M.Praveen Nawarathne (@zblockrat), Nebula Security (@nebusecurity), Nicolas Seriot, Peter Malone, Redon Gashi of Sentry, Robert Tran, Xiang Li from AOSP Lab @Nankai University, an anonymous researcher for their assistance. Mail We would like to acknowledge Himanshu Bharti (@Xpl0itme) From Khatima for their assistance. mDNSResponder We would like to acknowledge Hannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast and Daniel Gruss of Graz University of Technology, and Johanna Ullrich of the Interdisciplinary Transformation University (IT:U), Issa Sancho, Jian Zhou for their assistance. Notifications We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India, Himanshu Bharti @Xpl0itme From Khatima, Jan Rokita (rokita.me) for their assistance. Passwords We would like to acknowledge Catalin Lita of Moralis, Christian Kohlschütter, David Coomber of Info-Sec.CA, Lukasz Tulikowski at Software Cloud, Sujay Amin, an anonymous researcher for their assistance. RemoteServiceDiscovery We would like to acknowledge Tristan Madani (@TristanInSec) from Talence Security, an anonymous researcher for their assistance. Security We would like to acknowledge John Lussier, Masahiro Kawada (@kawakatz), Roman Zabicki for their assistance. Share Sheet We would like to acknowledge Atul Kishor Jaiswal, Benjamin Hornbeck for their assistance. Shortcuts We would like to acknowledge Owen Pawling (@owenpawling) for their assistance. VoiceOver We would like to acknowledge Hariji Vivek Pandey for their assistance. Wallet We would like to acknowledge an anonymous researcher for their assistance. WebKit We would like to acknowledge @TristanInSec, Maher Azzouzi, Meridian Miftari, OpenAI Codex Security - Amy Burnett, ret2happy, wwwlk for their assistance. WebKit Canvas We would like to acknowledge Utkarsh Pal for their assistance. Wi-Fi We would like to acknowledge E Vestavik (@Dynasty) for their assistance. Instructions on how to update your Apple Watch software are available at https://support.apple.com/kb/HT204641 To check the version on your Apple Watch, open the Apple Watch app on your iPhone and select "My Watch > General > About". Alternatively, on your watch, select "My Watch > General > About". All information is also posted on the Apple Security Releases web site: https://support.apple.com/100100. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmqoYqIACgkQ4Ifiq8DH 7PXTtBAAlBW+nN/PZ2KcAaHTpx+I50davvoKoKYZbrYVMkurpwQYAcIegc1jdbyS Hcpwh5v22qTCfF/B5DiBJxTbfqofCWhVNsTJcVX0nbYODsk1eXvqHCox9/lQ/iiU JUp49RZf1P9Wb/sfdnRXofqROEIw2ewuKaIsME/ut9ibfksfSMcW4hxV7gBZ2uCq p2RaUQdKgQJyRMqyc0pMBIbY/8+7v+4gZmkVSY/1mfUkntC9RfikH2AurExjyi6X g/yt9oMMeWsjE02fnv2Pa5/PlicCjUj+brGQPwHV4C5r8n6nMYqYxlwBxHYWf0k3 SSQknwLku9IQLOCbUC7Dl3AI9Z5wHVD5p6pTJ97mpxInIYwxL/jxcXyzz97g/l2H VKlzyQsQ3YQ9hEUmGrwcyusTg9ViHNI2KVWNypSRD84dp93rSyurlT2sPXtBUh+I +EZJ5bLvx2wRwulEqdpnABT0+n+NkS7ny1VEnXV42Gm4A2vGDqyNrcEiAnkaDT2d u3gLpAX5uPk3qQQL2oBKOPUhhWKoHg+3nHXEe4QJGJSbe1B4jkIaBwUvUjc9Eb77 Z6v+Zi68+QyLetDxrCERXVxrqQ5vyTQTPVO6p9q8j0XdcNaLFE3nDo5YTYDTmOtS sreR/9snY6jZ2BE+WBCbEC3XjfSLHa3GclOYMoIlpuJRIVFv+JM= =xvCq -----END PGP SIGNATURE----- _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- APPLE-SA-09-14-2026-7 watchOS 27 Apple Product Security via Fulldisclosure (Sep 22)
