Junglewise Threat Intelligence

CVE-2026-28967: Apple iOS and iPadOS denial of service via input validation

CVE-2026-28967 · Severity: medium · CVSS 4.9 · Published 2026-05-11

Technologies: Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple's mobile operating systems could allow an attacker with a specific network advantage to crash devices or services. This denial-of-service issue affects iPhones and iPads, potentially disrupting business operations or individual device availability. Users should update to the latest software versions to resolve this issue.

Technical details

A denial-of-service (DoS) vulnerability exists in iOS and iPadOS due to insufficient input validation. An attacker occupying a privileged network position (such as on a local or managed network) can exploit this flaw to trigger a system or service crash. The vulnerability was mitigated by Apple through improved input validation mechanisms. Patches are available in iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, and iPadOS 26.4.

Affected products

  • Apple iOS Before 18.7.7, before 26.4
  • Apple iPadOS Before 18.7.7, before 26.4

Timeline

  • 2026-03-24: patched: Initial release of fixes in iOS 26.4 and 18.7.7
  • 2026-05-11: disclosed: CVE published by Apple

References

Related threats