Junglewise Threat Intelligence

CVE-2026-28872: Apple iOS and iPadOS resource exhaustion in Calendar

CVE-2026-28872 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in the Calendar component of Apple mobile devices could allow a remote attacker to crash the system or make it unresponsive. This is caused by the device improperly handling certain inputs, leading to a depletion of system resources. Users should update to the latest software versions to maintain device availability and prevent service disruptions.

Technical details

A resource exhaustion vulnerability exists in the Calendar component of Apple iOS and iPadOS. The flaw is rooted in insufficient input validation, which allows a remote attacker to send specially crafted data that consumes excessive system resources. Successful exploitation results in a denial-of-service (DoS) condition, potentially causing application or system instability. Apple addressed this issue in iOS 18.7.9, iPadOS 18.7.9, iOS 26.4, and iPadOS 26.4 by implementing improved input validation logic.

Affected products

  • Apple iOS Earlier than 18.7.9, earlier than 26.4
  • Apple iPadOS Earlier than 18.7.9, earlier than 26.4

Timeline

  • 2026-03-24: patched: Initial patch released in iOS/iPadOS 26.4
  • 2026-05-11: advisory: Advisory published for iOS/iPadOS 18.7.9 and 26.4

References

Related threats