BlackTreeCVE IntelligenceOfficial source evidencesupport.apple.comVersioned article
Official source article · support.apple.com
About the security content of watchOS 26.4 - Apple Support
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs25
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2025-14524bearer token leak on cross-protocol redirect
- CVE-2026-43679An attacker with physical access to a locked Apple Watch may be able to view user contacts
- CVE-2026-28896An attacker may be able to cause unexpected system termination or read kernel memory
- CVE-2026-28886A null pointer dereference was addressed with improved input validation
- CVE-2026-28864A local attacker may gain access to user's Keychain items
- CVE-2026-20687A use after free issue was addressed with improved memory management
- CVE-2026-28868A logging issue was addressed with improved data redaction
- CVE-2026-28852A stack overflow was addressed with improved input validation
- CVE-2026-20665This issue was addressed through improved state management
- CVE-2026-20690An out-of-bounds access issue was addressed with improved bounds checking
- CVE-2026-28865An attacker in a privileged network position may be able to intercept network traffic
- CVE-2026-28878A privacy issue was addressed by removing sensitive data
- CVE-2026-28879A use-after-free issue was addressed with improved memory management
- CVE-2026-28860A local attacker may be able to modify the state of the Keychain
- CVE-2026-28867This issue was addressed with improved authentication
- CVE-2026-28859The issue was addressed with improved memory handling
- CVE-2026-28877An authorization issue was addressed with improved state management
- CVE-2026-28882This issue was addressed with improved checks
- CVE-2026-28870An information leakage was addressed with additional validation
- CVE-2026-28863A permissions issue was addressed with additional restrictions
- CVE-2026-20691An authorization issue was addressed with improved state management
- CVE-2026-28822An attacker may be able to cause unexpected app termination
- CVE-2026-28856An attacker with physical access to a locked device may be able to view sensitive user information
- CVE-2026-20698The issue was addressed with improved memory handling
- CVE-2025-64505LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index
Source and provenance
Original title: About the security content of watchOS 26.4 - Apple Support. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗