APPLE-SA-03-24-2026-7 watchOS 26.4
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要特定的开头。首先,我需要仔细阅读这篇文章,了解它的主要内容。 看起来这篇文章是关于苹果公司发布的一个安全更新,针对的是watchOS 26.4版本。里面提到了多个安全漏洞,每个漏洞都有CVE编号和发现者的信息。漏洞涉及的方面挺多的,比如网络认证、用户数据访问、音频处理、内核问题等等。 接下来,我需要把这些信息浓缩到100字以内。重点应该是说明这是苹果的安全更新,修复了多个漏洞,并且这些漏洞可能带来的影响是什么。同时,要提到这些漏洞是由不同的研究人员发现的。 可能的结构是:苹果发布watchOS 26.4安全更新,修复了多个漏洞,涉及网络认证、数据访问、音频处理和内核等多个方面。这些漏洞可能被攻击者利用来窃取信息或导致系统崩溃。研究人员包括Héloïse Gollier、Mathy Vanhoef等。 这样大概控制在100字左右,并且直接描述文章内容,没有使用“文章总结”之类的开头。 </think> 苹果发布watchOS 26.4安全更新,修复了包括网络认证、用户数据访问、音频处理和内核等多个方面的漏洞。这些漏洞可能导致信息泄露、系统崩溃或权限提升等问题。研究人员如Héloïse Gollier和Mathy Vanhoef等发现了相关问题并协助修复。 2026-3-29 03:11:5 Author: seclists.org(查看原文) 阅读量:5 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 24 Mar 2026 17:04:04 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-03-24-2026-7 watchOS 26.4

watchOS 26.4 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/126798.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

802.1X
Available for: Apple Watch Series 6 and later
Impact: An attacker in a privileged network position may be able to
intercept network traffic
Description: An authentication issue was addressed with improved state
management.
CVE-2026-28865: Héloïse Gollier and Mathy Vanhoef (KU Leuven)

Accounts
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-28877: Rosyna Keller of Totally Not Malicious Software

Audio
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: A use-after-free issue was addressed with improved memory
management.
CVE-2026-28879: Justin Cohen of Google

Audio
Available for: Apple Watch Series 6 and later
Impact: An attacker may be able to cause unexpected app termination
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-28822: Jex Amro

CoreMedia
Available for: Apple Watch Series 6 and later
Impact: Processing an audio stream in a maliciously crafted media file
may terminate the process
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
CVE-2026-20690: Hossein Lotfi (@hosselot) of Trend Micro Zero Day
Initiative

CoreUtils
Available for: Apple Watch Series 6 and later
Impact: A user in a privileged network position may be able to cause a
denial-of-service
Description: A null pointer dereference was addressed with improved
input validation.
CVE-2026-28886: Etienne Charron (Renault) and Victoria Martini (Renault)

Crash Reporter
Available for: Apple Watch Series 6 and later
Impact: An app may be able to enumerate a user's installed apps
Description: A privacy issue was addressed by removing sensitive data.
CVE-2026-28878: Zhongcheng Li from IES Red Team

curl
Available for: Apple Watch Series 6 and later
Impact: An issue existed in curl which may result in unintentionally
sending sensitive information via an incorrect connection
Description: This is a vulnerability in open source code and Apple
Software is among the affected projects. The CVE-ID was assigned by a
third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2025-14524

GeoServices
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: An information leakage was addressed with additional
validation.
CVE-2026-28870: XiguaSec

ImageIO
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: This is a vulnerability in open source code and Apple
Software is among the affected projects. The CVE-ID was assigned by a
third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2025-64505

Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to disclose kernel memory
Description: A logging issue was addressed with improved data redaction.
CVE-2026-28868: 이동하 (Lee Dong Ha of BoB 0xB6)

Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to leak sensitive kernel state
Description: This issue was addressed with improved authentication.
CVE-2026-28867: Jian Lee (@speedyfriend433)

Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-20698: DARKNAVY (@DarkNavyOrg)

Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-20687: Johnny Franks (@zeroxjf)

libxpc
Available for: Apple Watch Series 6 and later
Impact: An app may be able to enumerate a user's installed apps
Description: This issue was addressed with improved checks.
CVE-2026-28882: Ilias Morad (A2nkF) of Voynich Group, Duy Trần
(@khanhduytran0), @hugeBlack

Sandbox Profiles
Available for: Apple Watch Series 6 and later
Impact: An app may be able to fingerprint the user
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-28863: Gongyu Ma (@Mezone0)

Security
Available for: Apple Watch Series 6 and later
Impact: A local attacker may gain access to user's Keychain items
Description: This issue was addressed with improved permissions
checking.
CVE-2026-28864: Alex Radocea

Siri
Available for: Apple Watch Series 6 and later
Impact: An attacker with physical access to a locked device may be able
to view sensitive user information
Description: The issue was addressed with improved authentication.
CVE-2026-28856: an anonymous researcher

UIFoundation
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause a denial-of-service
Description: A stack overflow was addressed with improved input
validation.
CVE-2026-28852: Caspian Tarafdar

WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may prevent Content
Security Policy from being enforced
Description: This issue was addressed through improved state management.
WebKit Bugzilla: 304951
CVE-2026-20665: webb

WebKit
Available for: Apple Watch Series 6 and later
Impact: A malicious website may be able to process restricted web
content outside the sandbox
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 308248
CVE-2026-28859: greenbynox, Arni Hardarson

WebKit Sandboxing
Available for: Apple Watch Series 6 and later
Impact: A maliciously crafted webpage may be able to fingerprint the
user
Description: An authorization issue was addressed with improved state
management.
WebKit Bugzilla: 306827
CVE-2026-20691: Gongyu Ma (@Mezone0)

Additional recognition

AirPort
We would like to acknowledge Yashar Shahinzadeh, Saman Ebrahimnezhad,
Amir Safari, Omid Rezaii for their assistance.

Bluetooth
We would like to acknowledge Hamid Mahmoud for their assistance.

Captive Network
We would like to acknowledge Kun Peeks (@SwayZGl1tZyyy) for their
assistance.

CloudAttestation
We would like to acknowledge Suresh Sundaram, Willard Jansen for their
assistance.

CoreUI
We would like to acknowledge Peter Malone for their assistance.

Find My
We would like to acknowledge Salemdomain for their assistance.

GPU Drivers
We would like to acknowledge Jian Lee (@speedyfriend433) for their
assistance.

ICU
We would like to acknowledge Jian Lee (@speedyfriend433) for their
assistance.

Kernel
We would like to acknowledge DARKNAVY (@DarkNavyOrg), Kylian Boulard De
Pouqueville From Fuzzinglabs, Patrick Ventuzelo From Fuzzinglabs, Robert
Tran, Suresh Sundaram for their assistance.

libarchive
We would like to acknowledge Andreas Jaegersberger & Ro Achterberg of
Nosebeard Labs, Arni Hardarson for their assistance.

libc
We would like to acknowledge Vitaly Simonovich for their assistance.

Libnotify
We would like to acknowledge Ilias Morad (@A2nkF_) for their assistance.

LLVM
We would like to acknowledge Nathaniel Oh (@calysteon) for their
assistance.

Messages
We would like to acknowledge JZ for their assistance.

MobileInstallation
We would like to acknowledge Gongyu Ma (@Mezone0) for their assistance.

ppp
We would like to acknowledge Dave G. for their assistance.

Quick Look
We would like to acknowledge Wojciech Regula of SecuRing
(wojciechregula.blog), an anonymous researcher for their assistance.

Safari
We would like to acknowledge @RenwaX23, Farras Givari, Syarif Muhammad
Sajjad, Yair for their assistance.

Shortcuts
We would like to acknowledge Waleed Barakat (@WilDN00B) and Paul
Montgomery (@nullevent) for their assistance.

Siri
We would like to acknowledge Anand Mallaya, Tech consultant, Anand
Mallaya and Co., Harsh Kirdolia, Hrishikesh Parmar of Self-Employed for
their assistance.

Spotlight
We would like to acknowledge Bilge Kaan Mızrak, Claude & Friends: Risk
Analytics Research Group, Zack Tickman for their assistance.

Time Zone
We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from
Safran Mumbai India for their assistance.

UIKit
We would like to acknowledge AEC, Abhay Kailasia (@abhay_kailasia) from
Safran Mumbai India, Bishal Kafle (@whoisbishal.k), Carlos Luna (U.S.
Department of the Navy), Dalibor Milanovic, Daren Goodchild, JS De
Mattei, Maxwell Garn, Zack Tickman, fuyuu12, incredincomp for their
assistance.

Wallet
We would like to acknowledge Zhongcheng Li from IES Red Team of
ByteDance for their assistance.

Web Extensions
We would like to acknowledge Carlos Jeurissen, Rob Wu (robwu.nl) for
their assistance.

WebKit
We would like to acknowledge Vamshi Paili for their assistance.

WebKit Process Model
We would like to acknowledge Joseph Semaan for their assistance.

Wi-Fi
We would like to acknowledge Kun Peeks (@SwayZGl1tZyyy), an anonymous
researcher for their assistance.

Wi-Fi Connectivity
We would like to acknowledge Alex Radocea of Supernetworks, Inc for
their assistance.

Widgets
We would like to acknowledge Marcel Voß, Mitul Pranjay, Serok Çelik for
their assistance.

Instructions on how to update your Apple Watch software are
available at https://support.apple.com/kb/HT204641

To check the version on your Apple Watch, open the Apple Watch app
on your iPhone and select "My Watch > General > About".

Alternatively, on your watch, select "My Watch > General > About".

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmnDI0gACgkQ4Ifiq8DH
7PU5BBAAqUGF+tN9mIZSKdxPZeR4jQI9l+Er4lXyXzyYNi2vMAntYufDv6m+eucu
IXNWqlUH3pVTn67Yu17oMAYU3edhhW0tARQRPf9iuCz2qYfR/v0U7PIbe+52rt7v
xZBcA94xkofW6f55PWR17q7vklbAEy9xWLEbuBh9f3uSeOyIlQMineWykFWsXNEr
ah2iyWOgGjfOi+e5N1V1bE2Op4zn227VkjvHdQt6YqiJ25uCJXaPF1sJOvKIwlQ0
T9sJjpbYrmkchJQsEyv0x2YPFEGae1jQX8ceOmROkgl5a3egRwNnrR5C1StoJg2s
NaEjGMR0nZO+1CXFpprR7bsfu/W7YV1jQlrrZ/G68aYEO+eUD689EzHjOrxecL4V
hUJDjbbOzVtw84/1+yjk/3zL+aaKRC3bLo4X1zpqeuZaUddCtnBDGpdNed91qtfD
dMXIxoKG/YnP1WOnWCiOsIVSGbz1h8rqsknWpBXy48OvOgU2g67aCWC6D75w/YPW
9gjzEd1Xrz0ZzAT7qNGOX5ZWxzl4HSM1wTk4QgWHuFUY6AO6Bwv8WN7/pArkNrSN
8AocGOstA6P3eh+erbOB/uxU33wq0IBpuibciGntdnfemAYoQgOMbvRcJ9g0s1Kl
yyBa7YMCA0xzidPqQeczmpNHX/rVsbxTTiHeJDNGKCbjc8nqY9o=
=nvfM
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • APPLE-SA-03-24-2026-7 watchOS 26.4 Apple Product Security via Fulldisclosure (Mar 28)

文章来源: https://seclists.org/fulldisclosure/2026/Mar/22
如有侵权请联系:admin#unsafe.sh