Junglewise Threat Intelligence

CVE-2026-28960: Apple iOS and iPadOS denial-of-service in AirDrop

CVE-2026-28960 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

AirDrop is Apple's wireless file-sharing feature used on iPhones and iPads. A remote attacker positioned on the same network could exploit an input validation flaw to cause the device to stop responding or crash, disrupting user access to the device.

Technical details

CVE-2026-43667 is a reachable assertion vulnerability in the AirDrop component of iOS and iPadOS, triggered by improper input validation. An attacker in a privileged network position (e.g., on the same Wi-Fi or Bluetooth range) can send a specially crafted network packet to cause a denial-of-service condition. The vulnerability allows remote code to reach an assertion check that terminates the process without authentication required. The fix addresses this through improved input validation to reject malicious payloads before they reach the vulnerable code path.

Affected products

  • Apple iOS before 18.7.10
  • Apple iPadOS before 18.7.10

Timeline

  • 2026-08-17: patched: iOS 18.7.10 and iPadOS 18.7.10 released
  • 2026-09-14: advisory: Security advisory published by Apple

References

Related threats