Junglewise Threat Intelligence

CVE-2026-28846: Apple Multiple Operating Systems buffer overflow

CVE-2026-28846 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability has been identified in several Apple operating systems, including iOS, iPadOS, and macOS. This flaw could allow a remote attacker to cause applications to crash unexpectedly, potentially disrupting business operations or user productivity. Apple has released software updates to address this issue across its product lines.

Technical details

A buffer overflow vulnerability exists in multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) due to insufficient bounds checking. A remote attacker can exploit this flaw to cause unexpected application termination (denial-of-service). The issue was addressed by implementing improved bounds checking in the affected components. Patches are available in iOS 18.7.9, iOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and corresponding versions for other Apple platforms.

Affected products

  • Apple iOS Before 18.7.9, before 26.5
  • Apple iPadOS Before 18.7.9, before 26.5
  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats