Junglewise Threat Intelligence

CVE-2026-28958: This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPa

CVE-2026-28958 · Severity: medium · CVSS 5.5 · Published 2026-05-11

Technologies: Apple macOS, Apple Safari, Apple Iphone Os, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for iOS, macOS, and visionOS to address a vulnerability that could allow a malicious application to access sensitive user information. This flaw affects various Apple devices including iPhones, iPads, Macs, and the Vision Pro headset. If exploited, an unauthorized app could bypass standard data protections to view private user data, potentially compromising personal privacy.

Technical details

A vulnerability in Apple's operating systems (iOS, iPadOS, macOS Tahoe, and visionOS) was addressed with improved data protection mechanisms. The flaw allows a locally installed application to bypass certain data access restrictions to retrieve sensitive user information. While the specific component was not named in the primary CVE description, the fix involved enhancing data protection logic. The issue is resolved in version 26.5 of the affected operating systems through improved state management or additional validation. An attacker would typically need to entice a user to install a malicious application to exploit this vulnerability.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple visionOS Before 26.5
  • Apple Safari Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats