Apple ships nine coordinated security advisories patching Accelerate Framework image flaw across iOS, macOS, tvOS, watchOS and visionOS, plus Safari and Xcode bugs
Apple Product Security advisories APPLE-SA-09-14-2026-1, -2 and -4 through -10, dated Sep 14, 2026 and reposted to Full Disclosure on Sep 22, 2026, patch an Accelerate Framework flaw triggered by maliciously crafted images across iOS 27/26.7, macOS Tahoe 26.7…
Between 18:31:22 and 18:31:34 UTC on September 22, 2026, nine Apple Product Security advisories, all carrying the date 2026-09-14, were reposted to the Full Disclosure mailing list. Seven of them patch a vulnerability in the Accelerate Framework in which processing a maliciously crafted image may lead to unexpected behavior; the posted impact text is truncated in each case, so the full consequence is not stated. The affected platforms are iOS 27 and iPadOS 27 (APPLE-SA-09-14-2026-1, support doc 149034, iPhone 11 and later plus specified iPad Pro models), iOS 26.7 and iPadOS 26.7 (APPLE-SA-09-14-2026-2, doc 149041, iPhone 11 and later and iPad Pro 12.9-inch 3rd generation and later), macOS Tahoe 26.7 (APPLE-SA-09-14-2026-4, doc 149042, described as unexpected process behavior), macOS Sequoia 15.8 (APPLE-SA-09-14-2026-5, doc 149043), tvOS 27 (APPLE-SA-09-14-2026-6, doc 149036, Apple TV 4K 2nd generation and later), watchOS 27 (APPLE-SA-09-14-2026-7, doc 149037, Apple Watch Series 9 and later), and visionOS 27 (APPLE-SA-09-14-2026-8, doc 149038, all Apple Vision Pro models). Two additional advisories cover distinct issues. APPLE-SA-09-14-2026-9 for Safari 27, available on macOS Sequoia and macOS Tahoe (doc 149039), addresses a flaw in which a malicious website may be able to determine which apps a user has installed. APPLE-SA-09-14-2026-10 for Xcode 27, available on macOS Tahoe 26.6 and later (doc 149040), fixes a permissions issue that may allow an app to access user-sensitive data. All advisories reference Apple's security-update index at support article 100100. No CVE identifiers appear in any of the reports, and none states that any issue is being exploited in the wild. An advisory numbered APPLE-SA-09-14-2026-3 was not among the reports, so its contents are unknown. Device-availability listings for the iOS 27/iPadOS 27 advisory are truncated in the source text, and several impact descriptions are cut off mid-sentence.
- Nine advisories were reposted to Full Disclosure on 2026-09-22 between 18:31:22 and 18:31:34 UTC, all dated 2026-09-14: APPLE-SA-09-14-2026-1, -2, -4, -5, -6, -7, -8, -9 and -10.
- Seven advisories patch an Accelerate Framework flaw triggered by processing a maliciously crafted image that may lead to unexpected (process) behavior; the impact text is truncated in every posting, so full impact is unstated.
- Affected platforms and versions: iOS 27/iPadOS 27, iOS 26.7/iPadOS 26.7, macOS Tahoe 26.7, macOS Sequoia 15.8, tvOS 27, watchOS 27, visionOS 27, Safari 27, and Xcode 27.
- Device coverage per the advisories: iPhone 11 and later; iPad Pro 12.9-inch 3rd generation and later (26.7) and 4th generation and later (27, with the iPad Pro 11-inch listing truncated); Apple TV 4K 2nd generation and later; Apple Watch…
- Safari 27 (APPLE-SA-09-14-2026-9, doc 149039) fixes a privacy flaw on macOS Sequoia and macOS Tahoe where a malicious website may determine which apps a user has installed.
- Xcode 27 (APPLE-SA-09-14-2026-10, doc 149040) fixes a permissions issue on macOS Tahoe 26.6 and later that may allow an app to access user-sensitive data.
- Support document numbers cited: 149034 (iOS 27/iPadOS 27), 149041 (iOS 26.7/iPadOS 26.7), 149042 (macOS Tahoe 26.7), 149043 (macOS Sequoia 15.8), 149036 (tvOS 27), 149037 (watchOS 27), 149038 (visionOS 27), 149039 (Safari 27), 149040…
- No CVE identifiers are listed in any of the nine reports, and no report claims in-the-wild exploitation.
Coverage timelineoldest first · each row is one article
- · 4d agoAPPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27
Full Disclosure· 36
Apple published the iOS 27 and iPadOS 27 security advisory, with Accelerate Framework among the updated components.
- · 4d agoAPPLE-SA-09-14-2026-2 iOS 26.7 and iPadOS 26.7
Full Disclosure· 34
Apple released iOS 26.7 and iPadOS 26.7 security updates, including fixes affecting the Accelerate Framework.
- · 4d agoAPPLE-SA-09-14-2026-4 macOS Tahoe 26.7
Full Disclosure· 34
Apple's macOS Tahoe 26.7 advisory addresses an Accelerate Framework crafted-image bug.