Full Disclosure mailing list archives
APPLE-SA-09-14-2026-8 visionOS 27
From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 14 Sep 2026 15:09:24 -0700
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-09-14-2026-8 visionOS 27 visionOS 27 addresses the following issues. Information about the security content is also available at https://support.apple.com/149038. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Accelerate Framework Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted image may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-86882: Peter Malone APFS Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination or write kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84523: Cem Onat Karagun, an anonymous researcher App Store Available for: Apple Vision Pro (all models) Impact: A local app may be able to read a persistent account identifier Description: A permissions issue was addressed with additional restrictions. CVE-2026-86888: Zhongcheng Li (CK01) Apple Account Available for: Apple Vision Pro (all models) Impact: An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account Description: An authentication issue was addressed with improved state management. CVE-2026-20683: Dem0ns (@天府简易信工作室), Abdelhak Kherroubi, Jasminder Pal Singh, Lehan Dilusha Jayasingha (Sri Lanka) AppleAVD Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65407: Franco Belman at Blackwing Intelligence Audio Available for: Apple Vision Pro (all models) Impact: An app may be able to leak sensitive user information Description: A logic issue was addressed with improved checks. CVE-2026-65339: Mustafa Calap (@ordinal0, dbg.re), Meta Red Team X - Nik Tsytsarkin Authentication Services Available for: Apple Vision Pro (all models) Impact: An app may be able to delete credentials stored in Keychain Description: This issue was addressed by removing the vulnerable code. CVE-2026-86905: Ilya Andr (andrd3v) AuthKit Available for: Apple Vision Pro (all models) Impact: A local app may be able to read a persistent account identifier Description: A permissions issue was addressed with additional restrictions. CVE-2026-84583: Zhongcheng Li from IES Red Team AVEVideoEncoder Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination Description: The issue was addressed with improved checks. CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic Research AVEVideoEncoder Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination Description: A type confusion issue was addressed with improved memory handling. CVE-2026-84616: Peter Malone AVEVideoEncoder Available for: Apple Vision Pro (all models) Impact: A sandboxed app may be able to execute arbitrary code with kernel privileges Description: A race condition was addressed with improved state management. CVE-2026-84607: Ruslan Dautov BackgroundAssets Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: A logic issue was addressed with improved validation. CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security Bluetooth Available for: Apple Vision Pro (all models) Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65414 Bluetooth Available for: Apple Vision Pro (all models) Impact: An app may gain unauthorized access to Bluetooth Description: An authorization issue was addressed with improved state management. CVE-2026-84560: an anonymous researcher CloudKit Available for: Apple Vision Pro (all models) Impact: A local app may be able to read a persistent account identifier Description: An information disclosure issue was addressed with improved state management. CVE-2026-86895: Stanislav Jelezoglo CloudKit Available for: Apple Vision Pro (all models) Impact: An app may be able to read device name Description: A permissions issue was addressed with additional restrictions. CVE-2026-86893: Heiner Gerdes copyfile Available for: Apple Vision Pro (all models) Impact: An archive may be able to bypass Gatekeeper Description: A file quarantine bypass was addressed with additional checks. CVE-2026-65399: Rishabh Jain (rjcyber) of cyberplanet, Pasquale Scola, an anonymous researcher CoreMedia Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: A memory corruption issue was addressed by removing the vulnerable code. CVE-2026-64752: Nik Tsytsarkin CoreMedia Available for: Apple Vision Pro (all models) Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-86876: Chris Bailey - Short Circuit CoreMedia Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted video file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65344: Siyeong kim CoreML Available for: Apple Vision Pro (all models) Impact: A sandboxed app may be able to access restricted files Description: A permissions issue was addressed with improved path validation. CVE-2026-84624: AL Najafi, tamdao CoreText Available for: Apple Vision Pro (all models) Impact: Processing web content may lead to a denial-of-service Description: A null pointer dereference was addressed with improved input validation. CVE-2026-65412: Pavan Nallamothu CoreText Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84596: ret2happy, Meta Product Security CoreUI Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re) CoreUI Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted image may lead to unexpected app termination Description: A buffer overflow was addressed with improved bounds checking. CVE-2026-84571: stratan (@5tratan), Peter Malone CoreUI Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted asset catalog may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84511: Rahul Raj, stratan (@5tratan) DeviceCheck Available for: Apple Vision Pro (all models) Impact: An app may be able to read persistent device identifiers Description: An authorization issue was addressed with improved access control. CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill (@jjtech@infosec.exchange) File Bookmark Available for: Apple Vision Pro (all models) Impact: An app may be able to modify a file it only had permission to read Description: A permissions issue was addressed with additional restrictions. CVE-2026-43785: Junyeong Lee (jylab.github.io), Merrick Hare, Aditya Kumar, John Nzyuko Uvyu, Narendra Singh (@_3P1C) file_cmds Available for: Apple Vision Pro (all models) Impact: Extracting a maliciously crafted archive may allow an attacker to write arbitrary files Description: A path handling issue was addressed with improved validation. CVE-2026-84534: Geoffrey Lovelace FontParser Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted font file may lead to unexpected app termination Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-84524: an anonymous researcher FontParser Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read issue was addressed with improved input validation. CVE-2026-84597: Nik Tsytsarkin Foundation Available for: Apple Vision Pro (all models) Impact: An app may be able to cause a denial of service Description: A type confusion issue was addressed with improved memory handling. CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research Graphics Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with improved state handling. CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg), Jiyong Yang iCloud Available for: Apple Vision Pro (all models) Impact: An app may be able to identify a user across reinstalls Description: A privacy issue was addressed with improved handling of identifiers. CVE-2026-84606: Ilya Andr (andrd3v) ImageIO Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted image may result in disclosure of process memory Description: An uninitialized memory issue was addressed with improved memory initialization. CVE-2026-84564: Justin O'Leary ImageIO Available for: Apple Vision Pro (all models) Impact: Processing an image may lead to a denial-of-service Description: The issue was addressed with improved checks. CVE-2026-65347: Geonha Lee (@leegn4a) ImageIO Available for: Apple Vision Pro (all models) Impact: Processing an image may lead to arbitrary code execution Description: An integer overflow was addressed with improved input validation. CVE-2026-65346: Meta Red Team X - Nik Tsytsarkin ImageIO Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted image may result in memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan IOGPUFamily Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to memory corruption Description: The issue was addressed with improved memory handling. CVE-2026-64788: an anonymous researcher, f00l (@PPPF00L) and 3ndy1(@_3ndy1) and Minghao Lin@Y1nkoc and 云散花折, Arjanit Isufi IOKit Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영 IOMobileFrameBuffer Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds access issue was addressed with improved bounds checking. CVE-2026-65398: Chris Bailey - Short Circuit, Mustafa Calap (@ordinal0, dbg.re), David Strnadel, Meta Red Team X - Nik Tsytsarkin CVE-2026-64736: Ruslan Dautov, hxr1 IOSurfaceAccelerator Available for: Apple Vision Pro (all models) Impact: An app may be able to leak sensitive kernel state Description: An information leakage was addressed with additional validation. CVE-2026-64760: an anonymous researcher, Seiji Sakurai (@HeapSmasher), Franco Belman at Blackwing Intelligence Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-28968: genter0, Svetoslav Stolarov & Aisa Fox, Josh Maine of Calif.io, Dun Kernel Available for: Apple Vision Pro (all models) Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: A race condition was addressed with additional validation. CVE-2026-65415: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ryan Hileman via Xint Code (xint.io) Kernel Available for: Apple Vision Pro (all models) Impact: A remote attacker may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-65343: Drinor Selmanaj (Sentry), Surya Narayan Kushwaha Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved input validation. CVE-2026-65349: an anonymous researcher Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A double free issue was addressed with improved memory management. CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination Description: A race condition was addressed with improved state handling. CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination Description: A memory corruption issue was addressed with improved memory handling. CVE-2026-65377: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ye Zhang (@VAR10CK) of Baidu Security Kernel Available for: Apple Vision Pro (all models) Impact: An app with root privileges may be able to read uninitialized kernel memory Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.) Kernel Available for: Apple Vision Pro (all models) Impact: A malicious app may be able to gain root privileges Description: A permissions issue was addressed with additional restrictions. CVE-2026-43689: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs Kernel Available for: Apple Vision Pro (all models) Impact: Connecting to a malicious NFS server may disclose kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-43687: R4mbb of KRsecurity, Peter Malone Kernel Available for: Apple Vision Pro (all models) Impact: Connecting to a malicious NFS server may lead to kernel memory corruption Description: A use-after-free issue was addressed with improved memory management. CVE-2026-43686: Peter Malone Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to determine kernel memory layout Description: A memory initialization issue was addressed with improved memory handling. CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to disclose kernel memory Description: An information disclosure issue was addressed with improved memory management. CVE-2026-84530: Vladislav Shevchenko (Positive Technologies) Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination Description: A use after free issue was addressed with improved memory management. CVE-2026-84521: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Vision Pro (all models) Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A race condition was addressed with improved state handling. CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to disclose kernel memory Description: An out-of-bounds read was addressed with improved input validation. CVE-2026-86903: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling. CVE-2026-65330: Ashish Kunwar, Mikhail Lozhnikov of Positive Technologies, Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. CVE-2026-28935: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. Kernel Available for: Apple Vision Pro (all models) Impact: An app may be able to cause unexpected system termination Description: A type confusion issue was addressed with improved checks. CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. libarchive Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: A heap buffer overflow was addressed with improved bounds checking. CVE-2026-86870: Kitten Food Managed Configuration Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: A privacy issue was addressed with improved handling of files. CVE-2026-86883: Sindre Sorhus, Morris Richman (@morrisinlife), Stuart Wallace, Tristan Brennan MediaRemote Available for: Apple Vision Pro (all models) Impact: A sandboxed app may be able to access the System Keychain Description: An authorization issue was addressed with improved state management. CVE-2026-84628: Myeonghun Pak, Nathaniel Oh (@calysteon), Alan Banderas (@creeper4004) MobileBackup Available for: Apple Vision Pro (all models) Impact: An app may be able to modify protected parts of the file system Description: A path handling issue was addressed with improved validation. CVE-2026-65411: Rodolphe Brunetti (@eisw0lf) of Lupus Nova Model I/O Available for: Apple Vision Pro (all models) Impact: Opening a maliciously crafted file may lead to unexpected process termination Description: A buffer overflow was addressed with improved size validation. CVE-2026-84497: Yiğit Can YILMAZ (@yilmazcanyigit) Music Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-84615: Stanislav Jelezoglo NetworkExtension Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos NetworkExtension Available for: Apple Vision Pro (all models) Impact: An app may be able to identify what other apps a user has installed Description: An information disclosure issue was addressed with improved state management. CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team Photos Storage Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions. CVE-2026-84491: an anonymous researcher Photos Storage Available for: Apple Vision Pro (all models) Impact: An app may be able to fingerprint the user Description: This issue was addressed with additional entitlement checks. CVE-2026-84629: Stanislav Jelezoglo RealityKit Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-28966: stratan (@5tratan) RealityKit Available for: Apple Vision Pro (all models) Impact: Opening a maliciously crafted file may cause unexpected process termination or disclose process memory Description: An out-of-bounds read issue was addressed with improved input validation. CVE-2026-84532: Hongsik Kim (mnur), stratan (@5tratan) Reminders Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved checks. CVE-2026-65403: Rahul Raj Safe Browsing Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: This issue was addressed with additional entitlement checks. CVE-2026-86897: Stuart Wallace Sandbox Available for: Apple Vision Pro (all models) Impact: An app may be able to bypass network restrictions Description: A logic issue was addressed with improved validation. CVE-2026-84551: Issa Sancho Sandbox Profiles Available for: Apple Vision Pro (all models) Impact: An app may be able to fingerprint the user Description: A permissions issue was addressed with additional sandbox restrictions. CVE-2026-84625: Ilya Andr (andrd3v) of Positive Technologies, CJ Vana Sandbox Profiles Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions. CVE-2026-84603: Gongyu Ma (@Mezone0), CJ Vana, Stanislav Jelezoglo SceneKit Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted file may result in disclosure of process memory Description: An integer overflow was addressed with improved input validation. CVE-2026-84487: stratan (@5tratan), Dhiyanesh Selvaraj (@redroot97), Peter Malone SceneKit Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: The issue was addressed with improved memory handling. CVE-2026-84632: Peter Malone SceneKit Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: An integer overflow was addressed with improved input validation. CVE-2026-84620: Peter Malone SceneKit Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted 3D model may lead to memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter Malone CVE-2026-84611: Nathaniel Oh (@calysteon) SceneKit Available for: Apple Vision Pro (all models) Impact: Processing a maliciously crafted 3D scene may lead to unexpected process termination Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2026-84526: stratan (@5tratan) Security Available for: Apple Vision Pro (all models) Impact: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages Description: A certificate validation issue was addressed with improved certificate validation. CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier, Filip Olszak Shortcuts Available for: Apple Vision Pro (all models) Impact: A malicious shortcut may be able to send messages without user confirmation Description: An authorization issue was addressed with improved state management. CVE-2026-84600: Owen Pawling (@owenpawling) Software Update Available for: Apple Vision Pro (all models) Impact: An app may be able to modify protected system files Description: A permissions issue was addressed with improved path validation. CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team SpringBoard Available for: Apple Vision Pro (all models) Impact: An app may be able to cause a denial-of-service Description: This issue was addressed with additional entitlement checks. CVE-2026-86892: Lehan Dilusha Jayasingha Symptom Framework Available for: Apple Vision Pro (all models) Impact: A malicious application may be able to determine a user's current location Description: A privacy issue was addressed with improved private data redaction for log entries. CVE-2026-84513: Sindre Sorhus TCC Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: A logging issue was addressed with improved data redaction. CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom Time Zone Available for: Apple Vision Pro (all models) Impact: An app may be able to bypass certain Privacy preferences Description: A privacy issue was addressed by removing sensitive data. CVE-2026-86887: an anonymous researcher WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: An out-of-bounds access issue was addressed with improved bounds checking. WebKit Bugzilla: 317632 CVE-2026-64784: Janggoon Lee of Out of Bounds, OpenAI Codex Security - Amy Burnett WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected process termination Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 310457 CVE-2026-84635: Souta Sugiyama WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 313452 CVE-2026-43795: wwwlk WebKit Bugzilla: 318348 CVE-2026-65338: OpenAI Codex Security - Amy Burnett WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to memory corruption Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 318405 CVE-2026-65341: Henock Habte WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: A memory corruption vulnerability was addressed with improved locking. WebKit Bugzilla: 321480 CVE-2026-64782: Charles Kern, Seonwook Kim, Shubham Chaskar, lattice, Josef Korbel WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may disclose sensitive user information Description: A permissions issue was addressed by removing the vulnerable code. WebKit Bugzilla: 315121 CVE-2026-64753: Viggo Lekdorf WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: The issue was addressed with improved input validation. WebKit Bugzilla: 321484 CVE-2026-64781: Thomas Guillem WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: This issue was addressed through improved state management. WebKit Bugzilla: 321517 CVE-2026-65351: Niels Hofmans WebKit Bugzilla: 316996 CVE-2026-65340: Claudio Bozzato and Francesco Benvenuto of Cisco Talos, Josef Korbel (Citadelo) WebKit Bugzilla: 317142 CVE-2026-65337: OpenAI Codex Security - Amy Burnett WebKit Bugzilla: 317349 CVE-2026-65336: Josef Korbel WebKit Bugzilla: 316723 CVE-2026-65335: OpenAI Codex Security - Amy Burnett WebKit Bugzilla: 317603 CVE-2026-65333: OpenAI Codex Security - Amy Burnett WebKit Bugzilla: 317450 CVE-2026-65332: Kun Peeks (@SwayZGl1tZyyy), OpenAI Codex Security - Amy Burnett WebKit Bugzilla: 317611 CVE-2026-65331: OpenAI Codex Security - Amy Burnett WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 316347 CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected process termination Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 313703 CVE-2026-64787: 杉山 壮太, Shubham Chaskar WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: The issue was addressed with improved checks. WebKit Bugzilla: 316918 CVE-2026-64780: OpenAI Codex Security - Amy Burnett WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: A memory corruption issue was addressed with improved state management. WebKit Bugzilla: 316791 CVE-2026-65334: OpenAI Codex Security - Amy Burnett WebKit Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to memory corruption Description: A memory corruption issue was addressed with improved memory handling. WebKit Bugzilla: 317317 CVE-2026-43794: Dung Do (@_piers2) of Calif.io WebKit Available for: Apple Vision Pro (all models) Impact: Opening a maliciously crafted webarchive file may lead to universal cross-site scripting Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 3182711 CVE-2026-86898: Tomi Garcia (archyxsec) WebKit Canvas Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 313935 CVE-2026-64718: Niels Hofmans, OGINOME Tomohito, an anonymous researcher WebKit History Available for: Apple Vision Pro (all models) Impact: Visiting a maliciously crafted website may leak sensitive data Description: The issue was addressed with improved checks. WebKit Bugzilla: 322124 CVE-2026-64778: Mohit Negi WebKit Storage Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: A memory corruption vulnerability was addressed with improved locking. WebKit Bugzilla: 321485 CVE-2026-64779: Tommy DeVoss from Braze Security Team (@thedawgyg), Shubham Chaskar WebRTC Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to memory corruption Description: An out-of-bounds write issue was addressed with improved bounds checking. WebKit Bugzilla: 322761 CVE-2026-65391: Myungyong Lee WebRTC Available for: Apple Vision Pro (all models) Impact: Processing maliciously crafted web content may lead to memory corruption Description: An integer overflow was addressed with improved input validation. CVE-2026-65390: Kwak Kiyong (@Pwnkai23), Song Nuri Wi-Fi Connectivity Available for: Apple Vision Pro (all models) Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management. CVE-2026-84636: Jian Lee (@speedyfriend433) Additional recognition Accounts We would like to acknowledge Wojciech Regula of SecuRing (wojciechregula.blog) for their assistance. Apple Intelligence We would like to acknowledge an anonymous researcher for their assistance. AppleKeyStore We would like to acknowledge Abdurrahman Nafi, Francisco Knabe, Karol Mazurek (@Karmaz95) of AFINE, Somair Ansar, YOKI, an anonymous researcher, 晓娟 谢 for their assistance. AVEVideoEncoder We would like to acknowledge tamdao for their assistance. Bluetooth We would like to acknowledge Suresh Sundaram, Youssef Ahmed Saad for their assistance. Calendar We would like to acknowledge Dany Assuid, Jacob Hazak from Zero-Defense Labs, Varik Matevosyan, stratan (@5tratan) for their assistance. CipherML We would like to acknowledge Nils Hanff (@nils1729@chaos.social) of Hasso Plattner Institute for their assistance. CloudKit We would like to acknowledge Hikerell (Loadshine Lab) for their assistance. Compression We would like to acknowledge Tommy DeVoss from Braze Security Team (@thedawgyg) for their assistance. copyfile We would like to acknowledge Morris Richman (@morrisinlife) and Jian Lee (@speedyfriend433) for their assistance. CoreAnimation We would like to acknowledge Duy Trần (@khanhduytran0) for their assistance. CoreAudio We would like to acknowledge Patrick Saif / x.com/weezerOSINT / github.com/sai2fast for their assistance. CoreBluetooth - LE We would like to acknowledge Ashmit Sharma & Atul RV, Dun, Maliq Barnard, Nicholas C. of Onymos Inc. (onymos.com), Peter Malone, Robert M for their assistance. CoreGraphics We would like to acknowledge Gandalf4a of PKU-Changsha Institute for Computing and Digital Economy for their assistance. CoreMedia We would like to acknowledge Chris Bailey - Short Circuit for their assistance. CoreText We would like to acknowledge Jian Lee (@speedyfriend433) for their assistance. CoreUI We would like to acknowledge Peter Malone for their assistance. DataAccess We would like to acknowledge Adetayo Adebimpe (Cyboghostginx) for their assistance. FaceTime We would like to acknowledge Souhaib Naceri for their assistance. Files We would like to acknowledge an anonymous researcher for their assistance. iCloud We would like to acknowledge 3ndy1(@_3ndy1) and moyu for their assistance. ImageIO We would like to acknowledge Muhamad Syaiful, an anonymous researcher, songbird for their assistance. IOSurfaceAccelerator We would like to acknowledge Chanwit Muenprakoddee (ChemIndy), Franco Belman at Blackwing Intelligence, Iain Harkiss, an anonymous researcher, beist, hxr1 for their assistance. Kernel We would like to acknowledge Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Cem Onat Karagun, James Duffy (@0x4A616D657344), Lyutoon, Nebula Security (@nebusecurity), Nicolas Seriot, Peter Malone, Redon Gashi of Sentry, Robert Tran, Xiang Li from AOSP Lab @Nankai University, an anonymous researcher for their assistance. LaunchServices We would like to acknowledge Rosyna Keller of Totally Not Malicious Software (paradisefacade.com) for their assistance. mDNSResponder We would like to acknowledge Anton Pakhunov, Franciszek Kalinowski (striga.ai / isec.pl), Hannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast and Daniel Gruss of Graz University of Technology, and Johanna Ullrich of the Interdisciplinary Transformation University (IT:U), Issa Sancho, Jian Zhou, 章鱼哥@aipy (aipyaipy.com) for their assistance. Notifications We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India, Himanshu Bharti @Xpl0itme From Khatima, Jan Rokita (rokita.me) for their assistance. Passwords We would like to acknowledge Catalin Lita of Moralis, Christian Kohlschütter, David Coomber of Info-Sec.CA, Lukasz Tulikowski at Software Cloud, Sujay Amin, an anonymous researcher for their assistance. Printing We would like to acknowledge Stuart Wallace for their assistance. Pro Res We would like to acknowledge Meta Red Team X - Nik Tsytsarkin for their assistance. RemoteServiceDiscovery We would like to acknowledge Tristan Madani (@TristanInSec) from Talence Security, an anonymous researcher for their assistance. Safari We would like to acknowledge Dem0ns @天府简易信工作室 for their assistance. Sandbox Profiles We would like to acknowledge Lachlan Bauerochse for their assistance. Security We would like to acknowledge John Lussier, Roman Zabicki for their assistance. Share Sheet We would like to acknowledge Atul Kishor Jaiswal, Benjamin Hornbeck for their assistance. Shortcuts We would like to acknowledge Csaba Fitzl (@theevilbit) of Iru, Owen Pawling (@owenpawling) for their assistance. VoiceOver We would like to acknowledge Hariji Vivek Pandey for their assistance. WebKit We would like to acknowledge @TristanInSec, Behzad Najjarpour Jabbari (@_G4ru_), Big Bear, Eddy Tsalolikhin, Henock Habte, Henock Habte, Kenneth Hsu, Maher Azzouzi, Meridian Miftari, OpenAI Codex Security - Amy Burnett, Souta Sugiyama, Vitaly Simonovich, an anonymous researcher, hamayanhamayan, lattice, lebr0nli of National Yang Ming Chiao Tung University, Security and Systems Lab, ret2happy, wwwlk for their assistance. WebKit Canvas We would like to acknowledge Utkarsh Pal for their assistance. WebKit JavaScript Bindings We would like to acknowledge hamayanhamayan for their assistance. Wi-Fi We would like to acknowledge E Vestavik (@Dynasty) for their assistance. Instructions on how to update visionOS are available at https://support.apple.com/kb/HT214009 To check the software version on your Apple Vision Pro, open the Settings app and choose General > About. All information is also posted on the Apple Security Releases web site: https://support.apple.com/100100. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmqoYrkACgkQ4Ifiq8DH 7PWrzxAArZLZNtxDt3ahEmixhX218MjL/f/tG1WlZ/zhH1dXjKfleeuEUo+SQPr9 il6kMyNj7C83XSiAOQbDEUc8CNBFGa9Rria1vyQbzsi1bMPHU7YswicMhaYoQdgQ H3qupQqzsWhkK8jH0q26FAs2ZmBWRcxCkJ/kCc6YIw/mc3QwgMccuu88N59LL3qu YHz2oWZHunEzoA5x4xyLqali0zKQBJ3j1+wWBPijj0DqX2I23c8Vu+4CM5RoDsNL R0ca8DKY7y5t4OxemJTDNVpkN13mTT7cz6fw4Wg7Ob1M0ebgULx+OWh7NDQI4VUJ Tu1iz8R53sljSt6GofLrxSJ+A3torHgD3PdorfACc95zmIddPky8RHmu21DQDRz+ IP36NXtVZbCwpE4FLzP9P/B9nrFEWViVFMk6BM6rwpXTuOBKpLMvKEoE4FiFW5Wf XXO7YsKyIxQ72CEFV35FNlkHUTenKZ53cXgAuXqxyROG5+rnpRhMiiRjCQT/NYJ6 unHUyyNRn0BDUOcqZai8l+p/X7yTn6HLLdThu0AqGeWvBpVDuT0bT2PNhuT0CRNv 8AktDLD+OqgUchEVidaNnoGXgTVNpHzg4FWHpyTik7wMJP98J8fxA74vfotpkMYT Ohyt7ZrbflO/WOmCqNxRrCcSWyfSB1pr8/0dsBzgxa89k7TyD6o= =Tlee -----END PGP SIGNATURE----- _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- APPLE-SA-09-14-2026-8 visionOS 27 Apple Product Security via Fulldisclosure (Sep 22)
