visionOS 27’s Quiet Payload: Apple’s Security Bulletin for Vision Pro

Apple’s visionOS 27 release on September 14 was sold on Siri AI, Visual Intelligence, and new Environments. The quieter companion document is the security bulletin: About the security content of visionOS 27, which lists a long set of fixes for every Apple Vision Pro model.

Apple Vision Pro on display in an Apple Store
Apple Vision Pro. Photo: Seasider53 / Wikimedia Commons (CC BY 4.0).

What the bulletin actually patches

Apple does not publish severity scores in that document, but several entries matter for a spatial headset that lives on the face and on the network.

  • Kernel and sandbox edges. Multiple kernel issues cover unexpected termination, kernel memory disclosure, and corruption. One AVEVideoEncoder race condition (CVE-2026-84607) is described as letting a sandboxed app execute arbitrary code with kernel privileges.
  • Bluetooth. An out-of-bounds write is framed as a remote attacker path that may cause unexpected app termination or arbitrary code execution (CVE-2026-65414), alongside a local Bluetooth authorization fix.
  • WebKit / Safari. A dense block of WebKit entries covers crashes, memory corruption, use-after-free issues, and at least one universal XSS path via a malicious webarchive.
  • Identity and credentials. Fixes include a Sign In With Apple authentication-state flaw, Keychain credential deletion via Authentication Services, and several persistent-identifier disclosure cases across App Store, AuthKit, CloudKit, and DeviceCheck.
  • Media and 3D pipelines. ImageIO, CoreMedia, RealityKit, and SceneKit entries address malicious images, video, fonts, and 3D models — relevant for a platform that continually ingests spatial assets.

OpenCVE already indexes at least some of the CVEs listed in the Apple note, including account-identifier disclosure cases such as CVE-2026-86895.

Why this is the update owners should actually install

Feature notes get the headlines. The security page is the reason Vision Pro owners should treat visionOS 27 as more than a Siri rollout. The same Settings → General → Software Update path that delivers Siri AI, curved windows, and the Thórsmörk Environment also closes the bulletin’s kernel, Bluetooth, WebKit, and credential holes.

Apple’s release notes and MacRumors’ write-up confirm the update is free for both Vision Pro generations. Customizable Siri voices remain M5-only; the security content applies across all models listed in the bulletin.

Bottom line

If a Vision Pro is still on visionOS 26.x, the September 14 update is not optional polish. Install visionOS 27 for the AI features if you want them — and for the security content either way. Source of truth remains Apple’s bulletin at support.apple.com/en-us/149038.

Image credit: Apple Vision Pro product photo by Miyako Fujimiya (CC BY-SA 4.0) via Wikimedia Commons; in-body store display photo by Seasider53 (CC BY 4.0).

Leave a Comment