Junglewise Threat Intelligence

CVE-2026-28964: Apple iOS and iPadOS sensitive data access in CoreAnimation

CVE-2026-28964 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Iphone Os, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's CoreAnimation framework could allow a malicious application to access sensitive user information. This issue stems from how the system manages the state of the user interface, potentially leading to data exposure. Users are advised to update their devices to the latest software versions to protect their personal data.

Technical details

An inconsistent user interface issue exists within the CoreAnimation component of Apple's operating systems. The vulnerability is caused by improper state management, which can be exploited by a local application to bypass intended data protections and access sensitive user information. The issue was addressed in iOS 26.5, iPadOS 26.5, and visionOS 26.5 by implementing improved state management logic. No user interaction is required for exploitation beyond the execution of a malicious app on the device.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5
  • Apple visionOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats