Apple’s visionOS 27 release on September 14 was sold on Siri AI, Visual Intelligence, and new Environments. The quieter companion document is the security bulletin: About the security content of visionOS 27, which lists a long set of fixes for every Apple Vision Pro model.

What the bulletin actually patches
Apple does not publish severity scores in that document, but several entries matter for a spatial headset that lives on the face and on the network.
- Kernel and sandbox edges. Multiple kernel issues cover unexpected termination, kernel memory disclosure, and corruption. One AVEVideoEncoder race condition (
CVE-2026-84607) is described as letting a sandboxed app execute arbitrary code with kernel privileges. - Bluetooth. An out-of-bounds write is framed as a remote attacker path that may cause unexpected app termination or arbitrary code execution (
CVE-2026-65414), alongside a local Bluetooth authorization fix. - WebKit / Safari. A dense block of WebKit entries covers crashes, memory corruption, use-after-free issues, and at least one universal XSS path via a malicious webarchive.
- Identity and credentials. Fixes include a Sign In With Apple authentication-state flaw, Keychain credential deletion via Authentication Services, and several persistent-identifier disclosure cases across App Store, AuthKit, CloudKit, and DeviceCheck.
- Media and 3D pipelines. ImageIO, CoreMedia, RealityKit, and SceneKit entries address malicious images, video, fonts, and 3D models — relevant for a platform that continually ingests spatial assets.
OpenCVE already indexes at least some of the CVEs listed in the Apple note, including account-identifier disclosure cases such as CVE-2026-86895.
Why this is the update owners should actually install
Feature notes get the headlines. The security page is the reason Vision Pro owners should treat visionOS 27 as more than a Siri rollout. The same Settings → General → Software Update path that delivers Siri AI, curved windows, and the Thórsmörk Environment also closes the bulletin’s kernel, Bluetooth, WebKit, and credential holes.
Apple’s release notes and MacRumors’ write-up confirm the update is free for both Vision Pro generations. Customizable Siri voices remain M5-only; the security content applies across all models listed in the bulletin.
Bottom line
If a Vision Pro is still on visionOS 26.x, the September 14 update is not optional polish. Install visionOS 27 for the AI features if you want them — and for the security content either way. Source of truth remains Apple’s bulletin at support.apple.com/en-us/149038.
Image credit: Apple Vision Pro product photo by Miyako Fujimiya (CC BY-SA 4.0) via Wikimedia Commons; in-body store display photo by Seasider53 (CC BY 4.0).