Junglewise Threat Intelligence

CVE-2026-28931: Apple Multiple Operating Systems buffer overflow in NFS client

CVE-2026-28931 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability exists in Apple operating systems, including iOS, macOS, and watchOS, when connecting to network file storage. If a user connects their device to a malicious Network File System (NFS) server, the server could trigger a memory error on the device. This could potentially allow an attacker to disrupt the system or gain unauthorized access to sensitive kernel memory.

Technical details

A buffer overflow vulnerability exists in the NFS client implementation across Apple's ecosystem (iOS, iPadOS, macOS, tvOS, and watchOS). The issue stems from insufficient bounds checking when processing responses from an NFS server. An attacker controlling a malicious NFS server can exploit this by sending specially crafted network traffic to a connecting client, leading to kernel memory corruption. This could potentially result in arbitrary code execution with kernel privileges. The vulnerability was addressed in version 26.6 of the respective operating systems by improving bounds checking.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats