Junglewise Threat Intelligence

CVE-2026-28860: Apple Keychain input validation vulnerability allowing state modification

CVE-2026-28860 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's operating systems could allow a local attacker to modify the state of the Keychain, which is the secure storage system for passwords and sensitive credentials. If exploited, this could lead to the unauthorized modification or corruption of stored security data. This issue affects a wide range of Apple devices including iPhones, iPads, and Macs.

Technical details

A vulnerability exists in multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) where a local attacker can modify the state of the Keychain. The root cause is insufficient input validation within the Keychain component. By exploiting this flaw, an attacker with local access to the device can alter sensitive security state information. Apple has addressed this issue by implementing improved input validation across the affected platforms. Patches are available in iOS 18.7.7, macOS Sequoia 15.7.5, and other concurrent security updates.

Affected products

  • Apple iOS Before 18.7.7, before 26.4
  • Apple iPadOS Before 18.7.7, before 26.4
  • Apple macOS Sequoia Before 15.7.5
  • Apple macOS Sonoma Before 14.8.5
  • Apple macOS Tahoe Before 26.4
  • Apple tvOS Before 26.4
  • Apple visionOS Before 26.4
  • Apple watchOS Before 26.4

Timeline

  • 2026-03-24: patched: Initial release of fixes in various Apple OS versions
  • 2026-05-11: disclosed: CVE published by Apple and NVD

References

Related threats