Junglewise Threat Intelligence

CVE-2026-28962: Apple Multiple Operating Systems Information Disclosure via Web Content

CVE-2026-28962 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple macOS, Apple Safari, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple's web browsing engine could allow a malicious website to access sensitive user information. This affects iPhones, iPads, Macs, and Vision Pro headsets when processing specially crafted web content. Users are advised to update their devices to the latest software versions to prevent potential data exposure.

Technical details

An information disclosure vulnerability exists in Apple's operating systems (iOS, iPadOS, macOS, visionOS) and Safari browser. The flaw is triggered when the system processes maliciously crafted web content, which can lead to the unauthorized disclosure of sensitive user information. Apple addressed the issue by implementing improved access restrictions. The vulnerability is tracked as CVE-2026-28962 and has been patched in iOS 18.7.9, iPadOS 18.7.9, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, and visionOS 26.5.

Affected products

  • Apple iOS Before 18.7.9, before 26.5
  • Apple iPadOS Before 18.7.9, before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple visionOS Before 26.5
  • Apple Safari Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats