Junglewise Threat Intelligence

CVE-2026-28819: Apple Kernel out-of-bounds write in iOS and macOS

CVE-2026-28819 · Severity: medium · CVSS 5.4 · Published 2026-05-11

Technologies: Apple macOS, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in the core operating system of iPhones, iPads, and Macs could allow a malicious application to execute code with the highest level of system privileges (kernel). This could lead to a complete system takeover, allowing an attacker to bypass security protections, access any data on the device, or cause the system to crash. Users should update to the latest software versions to protect their devices.

Technical details

An out-of-bounds write vulnerability exists in the Apple Kernel across multiple operating systems, including iOS, iPadOS, and macOS. The flaw is caused by insufficient input validation when handling certain system calls or data structures. A local attacker, typically through a malicious application, can exploit this issue to write data beyond allocated memory buffers. This can result in arbitrary code execution with kernel-level privileges or a kernel panic leading to a denial-of-service (system termination). Apple addressed the issue by improving input validation and bounds checking in iOS 18.7.9, iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.

Affected products

  • Apple iOS Before 18.7.9
  • Apple iPadOS Before 18.7.9
  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats