Junglewise Threat Intelligence

CVE-2026-28936: Apple multiple OS improper input validation in file processing

CVE-2026-28936 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple macOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for iOS, iPadOS, macOS, and visionOS to address a vulnerability triggered by processing specially crafted files. If a user opens a malicious file, it could cause applications to crash unexpectedly or lead to other stability issues. This affects a wide range of Apple devices including iPhones, iPads, Macs, and Vision Pro headsets.

Technical details

An improper input validation vulnerability (CWE-20) exists in multiple Apple operating systems when processing maliciously crafted files. The issue was addressed through improved input checks to prevent unexpected application termination. An attacker could exploit this by tricking a user into opening a specifically formatted file, potentially leading to a denial-of-service condition for the affected application. The vulnerability is fixed in iOS 18.7.9, iOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7/14.8.8, macOS Tahoe 26.5, and visionOS 26.5.

Affected products

  • Apple iOS and iPadOS < 18.7.9, < 26.5
  • Apple macOS < 14.8.7, < 14.8.8, < 15.7.8, < 26.5
  • Apple visionOS < 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory

References

Related threats