Junglewise Threat Intelligence

CVE-2026-28935: Apple kernel memory corruption in IOMobileFrameBuffer

CVE-2026-28935 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple's kernel manages low-level device memory and system resources across iOS, iPadOS, and macOS devices. A flaw in the IOMobileFrameBuffer component allows apps to corrupt kernel memory or trigger unexpected system crashes, potentially enabling code execution at the highest system privilege level. This affects millions of iPhones, iPads, and Macs.

Technical details

CVE-2026-28935 is an out-of-bounds access vulnerability in the Apple kernel's IOMobileFrameBuffer component. The flaw allows a local unprivileged app to cause unexpected system termination or corrupt kernel memory through improved memory handling. No user interaction is required beyond installing and running a malicious app. An attacker can achieve denial of service or potentially escalate privileges, though the vulnerability requires local code execution. Patches are available in iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-28935 publicly disclosed by Apple
  • 2026-08-17: patched: iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2 released

References

Related threats