Junglewise Threat Intelligence

CVE-2026-28920: Apple Multiple Operating Systems Information Leakage via Malicious Website

CVE-2026-28920 · Severity: medium · CVSS 6.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in several Apple operating systems could allow a malicious website to access sensitive user information. This occurs when a user visits a specially crafted site designed to exploit a flaw in how the system validates data. This could lead to the unauthorized exposure of private data, potentially compromising user privacy and security. Apple has released software updates to address this issue across its device lineup.

Technical details

An information leakage vulnerability exists in multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw is triggered when a user visits a maliciously crafted website, which can exploit a lack of proper data validation to leak sensitive information. The root cause was addressed by implementing additional validation checks within the affected components. An attacker requires no special privileges but does require user interaction (visiting a website) to successfully exploit the vulnerability. Patches are available in iOS 18.7.9, iOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and other concurrent OS updates.

Affected products

  • Apple iOS Before 18.7.9, before 26.5
  • Apple iPadOS Before 18.7.9, before 26.5
  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats