Official source evidencesupport.apple.comVersioned article
Official source article · support.apple.com

About the security content of watchOS 26.4 - Apple Support

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs25

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2025-14524bearer token leak on cross-protocol redirect
  • CVE-2026-43679An attacker with physical access to a locked Apple Watch may be able to view user contacts
  • CVE-2026-28896An attacker may be able to cause unexpected system termination or read kernel memory
  • CVE-2026-28886A null pointer dereference was addressed with improved input validation
  • CVE-2026-28864A local attacker may gain access to user's Keychain items
  • CVE-2026-20687A use after free issue was addressed with improved memory management
  • CVE-2026-28868A logging issue was addressed with improved data redaction
  • CVE-2026-28852A stack overflow was addressed with improved input validation
  • CVE-2026-20665This issue was addressed through improved state management
  • CVE-2026-20690An out-of-bounds access issue was addressed with improved bounds checking
  • CVE-2026-28865An attacker in a privileged network position may be able to intercept network traffic
  • CVE-2026-28878A privacy issue was addressed by removing sensitive data
  • CVE-2026-28879A use-after-free issue was addressed with improved memory management
  • CVE-2026-28860A local attacker may be able to modify the state of the Keychain
  • CVE-2026-28867This issue was addressed with improved authentication
  • CVE-2026-28859The issue was addressed with improved memory handling
  • CVE-2026-28877An authorization issue was addressed with improved state management
  • CVE-2026-28882This issue was addressed with improved checks
  • CVE-2026-28870An information leakage was addressed with additional validation
  • CVE-2026-28863A permissions issue was addressed with additional restrictions
  • CVE-2026-20691An authorization issue was addressed with improved state management
  • CVE-2026-28822An attacker may be able to cause unexpected app termination
  • CVE-2026-28856An attacker with physical access to a locked device may be able to view sensitive user information
  • CVE-2026-20698The issue was addressed with improved memory handling
  • CVE-2025-64505LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index

Source and provenance

Original title: About the security content of watchOS 26.4 - Apple Support. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗