STIGQter STIGQter: STIG Summary: Apple visionOS 2 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 13 May 2026:

Apple visionOS 2 must implement the management setting: not allow automatic completion of Safari browser passcodes.

DISA Rule

SV-276393r1146675_rule

Vulnerability Number

V-276393

Group Title

PP-MDF-993300

Rule Version

AVOS-02-010600

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Install a configuration profile to disable the AutoFill capability in the Safari app.

Check Contents

Review configuration settings to confirm "Enable autofill" is unchecked.

This check procedure is performed on both the Apple visionOS management tool and the Vision Pro.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple visionOS management tool, verify "Enable autofill" is unchecked.

Alternatively, verify the text "<key>safariAllowAutoFill</key><false>" appears in the configuration profile (.mobileconfig file).

On the Vision Pro:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the configuration profile from the visionOS management tool containing the management policy.
5. Tap "Restrictions".
6. Verify "Auto-fill in Safari not allowed" is present.

If "Enable autofill" is checked in the Apple visionOS management tool, "<key>safariAllowAutoFill</key><true>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Auto-fill in Safari not allowed", this is a finding.

Vulnerability Number

V-276393

Documentable

False

Rule Version

AVOS-02-010600

Severity Override Guidance

Review configuration settings to confirm "Enable autofill" is unchecked.

This check procedure is performed on both the Apple visionOS management tool and the Vision Pro.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple visionOS management tool, verify "Enable autofill" is unchecked.

Alternatively, verify the text "<key>safariAllowAutoFill</key><false>" appears in the configuration profile (.mobileconfig file).

On the Vision Pro:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the configuration profile from the visionOS management tool containing the management policy.
5. Tap "Restrictions".
6. Verify "Auto-fill in Safari not allowed" is present.

If "Enable autofill" is checked in the Apple visionOS management tool, "<key>safariAllowAutoFill</key><true>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Auto-fill in Safari not allowed", this is a finding.

Check Content Reference

M

Target Key

5713