Home / mailings APPLE-SA-07-27-2026-6 watchOS 26.6
Posted on 28 July 2026
Apple Security-announceAPPLE-SA-07-27-2026-6 watchOS 26.6
watchOS 26.6 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/128068.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
Accounts Framework
Available for: Apple Watch Series 6 and later
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved data protection.
CVE-2026-64733: Rosyna Keller of Totally Not Malicious Software
(paradisefacade.com)
App Store
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
CVE-2026-43801: Rahul Raj
Apple Neural Engine
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-28928: Dun
Audio
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause a denial-of-service
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-64725: Seonung Park, ALTV!ST (altvi.st/)
AuthKit
Available for: Apple Watch Series 6 and later
Impact: An app may be able to fingerprint the user
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-43730: David Strnadel
AVEVideoEncoder
Available for: Apple Watch Series 6 and later
Impact: An app may be able to execute arbitrary code with kernel
privileges
Description: A buffer overflow was addressed with improved size
validation.
CVE-2026-64747: Franco Belman at Blackwing Intelligence
CloudAttestation
Available for: Apple Watch Series 6 and later
Impact: A maliciously crafted app may be able to bypass code signing
enforcement
Description: A validation issue was addressed with improved input
sanitization.
CVE-2026-43813: Anton Pakhunov
Contacts
Available for: Apple Watch Series 6 and later
Impact: An app may be able to add contacts without user authorization
Description: An authorization issue was addressed with improved
validation.
CVE-2026-64746: Rodolphe BRUNETTI (@eisw0lf) of Lupus Nova, Daniel
Febrero
Contacts
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted contact may leak sensitive data
Description: The issue was addressed with improved checks.
CVE-2026-64734: Daniel Williams
CoreAudio
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted audio file may corrupt process
memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43673: Anonymous working with TrendAI Zero Day Initiative
CoreAudio
Available for: Apple Watch Series 6 and later
Impact: Processing an audio stream in a maliciously crafted media file
may terminate the process
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-43744: Mathis Mansi=C3=A8re, an anonymous researcher
CoreAudio
Available for: Apple Watch Series 6 and later
Impact: A remote attacker may be able to cause unexpected system
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-43803: Rahul Raj
CoreMedia
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted video file may lead to
unexpected app termination
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2026-43711: James Duffy (@0x4A616D657344)
CoreMedia
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-43759: =EC=9D=B4=EC=9E=AC=EC=98=81, Rajdip Dey Sarkar, Arni =Hardarson (Neonix Security)
curl
Available for: Apple Watch Series 6 and later
Impact: Authentication credentials may be sent to a server on another
origin
Description: This is a vulnerability in open source code and Apple
Software is among the affected projects. The CVE-ID was assigned by a
third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2026-3784
CVE-2026-3783
Data Detectors UI
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-43758: HvxyZLF
Foundation
Available for: Apple Watch Series 6 and later
Impact: A malicious app may be able to access protected user data
Description: The issue was addressed with improved input sanitization.
CVE-2026-43714: an anonymous researcher
FrontBoard
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: This issue was addressed by using HTTPS when sending
information over the network.
CVE-2026-64742: Hu=E1=BB=B3nh T=E1=BA=A5n Ng=C3=A0n
Game Center
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved data protection.
CVE-2026-43796: Ilya Andr (andrd3v) of Positive Technologies, Stanislav
Jelezoglo
Heimdal
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause a denial-of-service
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-64692: Redon Gashi
ImageIO
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted texture may lead to unexpected
app termination
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-43780: Michael DePlante (@izobashi) of TrendAI Zero Day
Initiative
ImageIO
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted image may corrupt process
memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64716: Arni Hardarson, Jonathan Alush-Aben, Peter Malone
ImageIO
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: The issue was addressed with improved bounds checks.
CVE-2026-64758: =EC=A7=84=EA=B7=9C=EC=A0=95 (Gyujeong Jin, @G1uN4sh)
ImageIO
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted file may lead to a
denial-of-service
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-64754: PETOWORKS=EC=9D=98 Bugeun Choi (@Bugeun), Rahul Raj
ImageIO
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted image may lead to a
denial-of-service
Description: A type confusion issue was addressed with improved checks.
CVE-2026-64693: Geonha Lee (@leegn4a)
IOGPUFamily
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-43743: Lyutoon, Dun
IOKit
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: A race condition was addressed with improved state
handling.
CVE-2026-43805: =EC=9D=B4=EC=9E=AC=EC=98=81
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-43778: f0r of MurphySec, Feng Xue and XGPT of ThreatBook,
Mahmoud Abdelmoniem, an anonymous researcher, Wang Yu, Lyutoon, Hiroki
Imai (LAC Co., Ltd.), DARKNAVY (@DarkNavyOrg), F=C3=A1bio Lu=C3=ADs =@scanpt,
Nicolas Rabrenovic
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to disclose kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64709: Pasquale Scola, Billy Jheng Bing Jhong and Pan Zhenpeng
(@Peterpan0927) of STAR Labs SG Pte. Ltd.
Kernel
Available for: Apple Watch Series 6 and later
Impact: A remote attacker may be able to bypass network filters
Description: An inconsistent user interface issue was addressed with
improved state management.
CVE-2026-64735: Gor Aleksanyan
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-43739: impost0r (ret2plt), Ruslan Dautov, Aleksandr Tarasikov,
jay, Dhiyanesh Selvaraj (@redroot97), Vinay Kumar Rasala (Xplo8E) from
Appknox, Lyutoon, DongJun Kim (smlijun) with UIUC, Hwiwon Lee (hwiwonl)
with UIUC, Jongseong Kim (nevul37) with UIUC, Younggi Park (grill66)
with UIUC, Peter Malone, an anonymous researcher, Hari Shanmugam (The
Hxr1), Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR
Labs SG Pte. Ltd., Marco Grassi, Dun, Daniele Castronovo, Michal
Kosiorek
CVE-2026-43816: Josh Maine of Calif.io, Ruslan Dautov, =EC=9E=AC=EC=98=81 ==EC=A0=95, @rootxran
(Rao Ali Nawaz), Chanwit Muenprakoddee (ChemIndy), an anonymous
researcher, Ye Zhang (@VAR10CK) of Baidu Security, Franco Belman at
Blackwing Intelligence, Christian Figueroa, Johnny Franks (@zeroxjf),
Ashmit Sharma & Atul RV, Peter Malone, Muhamad Syaiful, Muneeb Amin
Bhat, Dhiyanesh Selvaraj (@redroot97), Ali Marzouq, Bountyy Oy - Mihalis
Haatainen, Huy Nguyen (@34306) of Calif.io
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-43822: Eddy Tsalolikhin, Michal Kosiorek
CVE-2026-64729: Josh Maine of Calif.io, beist, Adam Doup=C3=A9 of ASU =SEFCOM,
Dun, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR
Labs SG Pte. Ltd., Johnny Franks (@zeroxjf)
CVE-2026-43814: Somair Ansar, Huy Nguyen (@34306) of Calif.io
CVE-2026-64700: Asjid Kalam (@odinshell)
CVE-2026-43799: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
Kernel
Available for: Apple Watch Series 6 and later
Impact: Connecting to a malicious NFS server may lead to kernel memory
corruption
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-28931: Redon Gashi, Abhijeet Singh (linkedin.com/in/abhiunix/),
Peter Malone, Omar Cerrito
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-43817: Huy Nguyen (@34306) of Calif.io
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: The issue was addressed with improved input sanitization.
CVE-2026-43724: impost0r (ret2plt), Hyunwoo Kim (@v4bel)
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-43769: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
Kernel
Available for: Apple Watch Series 6 and later
Impact: A remote user may be able to cause unexpected system termination
or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43810: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination
Description: A memory initialization issue was addressed with improved
memory handling.
CVE-2026-64775: Ryan Hileman via Xint Code (xint.io)
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: This issue was addressed with improved input validation.
CVE-2026-39868: Vladislav Shevchenko (Positive Technologies), Ye Zhang
(@VAR10CK) of Baidu Security, Billy Jheng Bing Jhong and Pan Zhenpeng
(@Peterpan0927) of STAR Labs SG Pte. Ltd.
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-64720: an anonymous researcher, Asjid Kalam (@odinshell), Jian
Zhou and Ye Zhang
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-64751: N.M.Praveen Nawarathne (@zblockrat)
Kernel
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: This issue was addressed through improved state management.
CVE-2026-64721: Lukas Gerlach
libc
Available for: Apple Watch Series 6 and later
Impact: A malicious app may be able to break out of its sandbox
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-28973: an anonymous researcher
Libnotify
Available for: Apple Watch Series 6 and later
Impact: An attacker may be able to cause unexpected app termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-64739: Feng Xue and XGPT of ThreatBook, Dun
libxslt
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: A double free issue was addressed with improved memory
management.
CVE-2026-43706: Tristan Madani (@TristanInSec) from Talence Security
libxslt
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: The issue was addressed with improved memory handling.
CVE-2026-43703: Tristan Madani (@TristanInSec) from Talence Security
Managed Configuration
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-64743: Daniel Febrero
mDNSResponder
Available for: Apple Watch Series 6 and later
Impact: An attacker on the local network may be able to cause a
denial-of-service
Description: The issue was addressed with improved memory handling.
CVE-2026-64724: Daisuke Hatakeyama (@SYZD Research)
MediaRemote
Available for: Apple Watch Series 6 and later
Impact: An app may be able to gain root privileges
Description: A path handling issue was addressed with improved
validation.
CVE-2026-43723: Richard Zana, Andreas Jaegersberger & Ro Achterberg of
Nosebeard Labs
MobileAccessoryUpdater
Available for: Apple Watch Series 6 and later
Impact: A malicious accessory may be able to cause unexpected app
termination
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-43807: Tristan Madani (@TristanInSec) from Talence Security
Sandbox Profiles
Available for: Apple Watch Series 6 and later
Impact: An app may be able to read a persistent device identifier
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-64741: =E5=BD=A6=E8=BE=B0
SceneKit
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination or arbitrary code execution
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-64766: stratan (@5tratan)
CVE-2026-64765: stratan (@5tratan)
SceneKit
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-64764: stratan (@5tratan)
SceneKit
Available for: Apple Watch Series 6 and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed by removing the
vulnerable code.
CVE-2026-64763: stratan (@5tratan)
Siri
Available for: Apple Watch Series 6 and later
Impact: An app may be able to access sensitive user data
Description: An information disclosure issue was addressed by removing
the vulnerable code.
CVE-2026-43800: Stanislav Jelezoglo
Web Extensions
Available for: Apple Watch Series 6 and later
Impact: A malicious web extension may be able to cause an unexpected
process crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 314642
CVE-2026-43704: dr3dd
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may result in the
disclosure of process memory
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 308046
CVE-2026-43740: Arni Hardarson, Nathaniel Oh (@calysteon)
WebKit
Available for: Apple Watch Series 6 and later
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 313357
CVE-2026-43735: Gurpreet Shergill, Merrick Hare, Drinor Selmanaj
(Sentry), Khai Tran, John Lussier, Rhyru9, Kwak Kiyong, Song Nuri
WebKit
Available for: Apple Watch Series 6 and later
Impact: Websites may know if the user has visited a given link
Description: This issue was addressed with improved checks.
WebKit Bugzilla: 316827
CVE-2026-64713: Kwak Kiyong, Song Nuri
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313693
CVE-2026-43734: Jonathan Alush-Aben
WebKit Bugzilla: 313857
CVE-2026-43726: stratan (@5tratan) of Almamater Technologies, Josef
Korbel (Citadelo), Tristan Madani (@TristanInSec) from Talence Security,
Gia Bui (@yabeow) from Calif.io, Narendra Singh (@_3P1C)
WebKit Bugzilla: 314398
CVE-2026-43709
WebKit Bugzilla: 315161
CVE-2026-43742: =D0=AE=D0=BB=D0=B8=D1=8F =D0=9C=D0=B5=D1=80=D1=86=D0=B0=D0==BB=D0=BE=D0=B2=D0=B0
WebKit Bugzilla: 317227
CVE-2026-43699: Tommy DeVoss from Braze Security Team (@thedawgyg)
WebKit
Available for: Apple Watch Series 6 and later
Impact: Visiting a website that frames malicious content may lead to UI
spoofing
Description: The issue was addressed with improved UI.
WebKit Bugzilla: 311660
CVE-2026-64730: Kagami Rosylight of Mozilla
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A path handling issue was addressed with improved
validation.
WebKit Bugzilla: 313085
CVE-2026-43732: Nan Wang (@eternalsakura13)
WebKit
Available for: Apple Watch Series 6 and later
Impact: An app may be able to read files outside of its sandbox
Description: An access issue was addressed with improved access
restrictions.
WebKit Bugzilla: 314867
CVE-2026-43821: Brian Carpenter
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 314115
CVE-2026-43731: dr3dd
WebKit Bugzilla: 313577
CVE-2026-43715: Milad Nasr and Nicholas Carlini with Claude, Anthropic
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313691
CVE-2026-43727: Tommy DeVoss from Braze Security Team (@thedawgyg), Gia
Bui (@yabeow) from Calif.io, Gurpreet Shergill
WebKit Bugzilla: 313521
CVE-2026-64783: =E6=9D=89=E5=B1=B1 =E5=A3=AE=E5=A4=AA, lattice, Behzad =Najjarpour Jabbari (@_G4ru_),
Junyeong Lee, Mooth.ai, OGINOME Tomohito, Using GLM =46rom Z.AI, Gia Bui
(@yabeow) from Calif.io
WebKit
Available for: Apple Watch Series 6 and later
Impact: A malicious website may be able to process restricted web
content outside the sandbox
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 312832
CVE-2026-43725: Luke Francis
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 312781
CVE-2026-43663: stratan (@5tratan) of Almamater Technologies, Soyeon
Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit
(@h3xr4bb1t) and NiNi (@terrynini38514) of DEVCORE Research Team, Using
GLM =46rom Z.AI, Tristan Madani (@TristanInSec) from Talence Security,
Brian Carpenter
WebKit Bugzilla: 313528
CVE-2026-39872: Utkarsh Pal, Ignacio Sanmillan (@ulexec)
WebKit Bugzilla: 314235
CVE-2026-43712: Kwak Kiyong, Song nuri, Tristan Madani (@TristanInSec)
from Talence Security
WebKit
Available for: Apple Watch Series 6 and later
Impact: Maliciously crafted web content may violate iframe sandboxing
policy
Description: A permissions issue was addressed with improved validation.
WebKit Bugzilla: 313220
CVE-2026-64728: an anonymous researcher
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
WebKit Bugzilla: 317231
CVE-2026-43676: Mateusz Krzywicki (iVerify.io), dr3dd, Tommy DeVoss from
Braze Security Team (@thedawgyg)
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A memory corruption issue was addressed with improved state
management.
WebKit Bugzilla: 315082
CVE-2026-64757: Milad Nasr and Nicholas Carlini with Claude, Anthropic
WebKit
Available for: Apple Watch Series 6 and later
Impact: Visiting a website may leak sensitive data
Description: A permissions issue was addressed with additional
restrictions.
WebKit Bugzilla: 314806
CVE-2026-43713: Jody Ritonga
WebKit
Available for: Apple Watch Series 6 and later
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 315306
CVE-2026-43708: Behzad Najjarpour Jabbari (@_G4ru_)
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: A memory corruption issue was addressed with improved
memory handling.
WebKit Bugzilla: 315951
CVE-2026-43707: stratan (@5tratan) of Almamater Technologies, OpenAI
Codex Security - Amy Burnett
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: A type confusion issue was addressed with improved checks.
WebKit Bugzilla: 314528
CVE-2026-43705: dr3dd
WebKit
Available for: Apple Watch Series 6 and later
Impact: A malicious website may be able to process restricted web
content outside the sandbox
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 315004
CVE-2026-43701: Aaron Grattafiori - NVIDIA AI Red Team
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: An out-of-bounds write issue was addressed with improved
input validation.
WebKit Bugzilla: 315365
CVE-2026-43745: OpenAI Codex Security - Amy Burnett, Khai Tran
WebKit
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A cross-origin issue was addressed with improved tracking
of security origins.
WebKit Bugzilla: 315368
CVE-2026-43700: Vitaly Simonovich, Christian Meurer Xavier
WebKit Canvas
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313175
CVE-2026-43720: Gia Bui (@yabeow) from Calif.io, Josef Korbel
WebKit Bugzilla: 313935
CVE-2026-64718: OGINOME Tomohito, an anonymous researcher
WebKit Storage
Available for: Apple Watch Series 6 and later
Impact: A malicious website may be able to silently hijack clipboard
data
Description: This issue was addressed through improved state management.
WebKit Bugzilla: 313478
CVE-2026-43721: Idan Masas
WebRTC
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
WebKit Bugzilla: 317324
CVE-2026-28979
WebRTC
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A stack overflow was addressed with improved input
validation.
WebKit Bugzilla: 313350
CVE-2026-43718: Nan Wang (@eternalsakura13)
WebRTC
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313351
CVE-2026-43717: Nan Wang (@eternalsakura13)
WebRTC
Available for: Apple Watch Series 6 and later
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
WebKit Bugzilla: 319404
CVE-2026-64719: Shaheen Fazim
Wi-Fi
Available for: Apple Watch Series 6 and later
Impact: An attacker in physical proximity may be able to corrupt process
memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64726: Mathis Mansi=C3=A8re, Peter Malone
Additional recognition
CoreMedia
We would like to acknowledge yaohway for their assistance.
Heimdal
We would like to acknowledge Surya Narayan Kushwaha for their
assistance.
Kernel
We would like to acknowledge Billy Jheng Bing Jhong and Pan Zhenpeng
(@Peterpan0927) of STAR Labs SG Pte. Ltd., James Duffy ( @0x4A616D657344
), Tristan Rousseau, Vladislav Shevchenko (Positive Technologies),
YingMuo (@YingMuo) of DEVCORE Research Team for their assistance.
libxslt
We would like to acknowledge Kubilay Berk Alkan for their assistance.
Security
We would like to acknowledge John Lussier, Oleh Konko of 1seal
(1seal.org), alick for their assistance.
WebKit
We would like to acknowledge Gurpreet Shergill, Henock Habte, Jaya Surya
Kommireddy, Jaya surya Kommireddy, Lukas Knittel (@kunte_ctf) of
Ruhr-University Bochum, Nikos Fanourakis of Technical University of
Crete, Sotiris Ioannidis of Technical University of Crete, Panagiotis
Ilia of Cyprus University of Technology, and Kostas Drakonakis of
Technical University of Crete, Souta Sugiyama, Tony Gorez (@tonygo_) for
Reverse Society, Vitaly Simonovich, Youngjoon Kim of Team-Atlanta &
sslab at Georgia Tech, s3zer0 for their assistance.
WebKit Storage
We would like to acknowledge Gurpreet Shergill, Luke Francis, Milad Nasr
and Nicholas Carlini with Claude, Anthropic, Oleh Konko of 1seal
(1seal.org), Vitaly Simonovich for their assistance.
Instructions on how to update your Apple Watch software are available at
https://support.apple.com/kb/HT204641
To check the version on your Apple Watch, open the Apple Watch app on
your iPhone and select "My Watch > General > About".
Alternatively, on your watch, select "My Watch > General > About".
All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
