Junglewise Threat Intelligence

CVE-2026-28928: Apple multiple operating systems use after free memory corruption

CVE-2026-28928 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

A memory management vulnerability in Apple operating systems could allow a malicious application to cause a sudden system crash or termination. This affects iPhones, iPads, Macs, Apple TVs, and Apple Watches. While primarily a stability risk, such flaws can sometimes be used to disrupt device operations.

Technical details

A use-after-free vulnerability exists in multiple Apple operating systems due to improper memory management. A local application can exploit this flaw to trigger an unexpected system termination (denial of service). The issue was addressed by improving memory management logic. Affected platforms include iOS/iPadOS, macOS Tahoe, tvOS, and watchOS, all prior to version 26.6.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS < 26.6 (Tahoe)
  • Apple tvOS < 26.6
  • Apple watchOS < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats