Executive brief
Apple's kernel manages low-level device memory and system resources across iOS, iPadOS, and macOS devices. A flaw in the IOMobileFrameBuffer component allows apps to corrupt kernel memory or trigger unexpected system crashes, potentially enabling code execution at the highest system privilege level. This affects millions of iPhones, iPads, and Macs.
Technical details
CVE-2026-28935 is an out-of-bounds access vulnerability in the Apple kernel's IOMobileFrameBuffer component. The flaw allows a local unprivileged app to cause unexpected system termination or corrupt kernel memory through improved memory handling. No user interaction is required beyond installing and running a malicious app. An attacker can achieve denial of service or potentially escalate privileges, though the vulnerability requires local code execution. Patches are available in iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-28935 publicly disclosed by Apple
- 2026-08-17: patched: iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2 released