Junglewise Threat Intelligence

CVE-2026-28985: Apple Multiple Operating Systems null pointer dereference

CVE-2026-28985 · Severity: medium · CVSS 6.2 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's operating systems for iPhone, iPad, Mac, and Apple TV could allow an attacker on the same local network to crash the device. This results in a denial-of-service, potentially disrupting operations or causing temporary loss of access to the affected hardware. Users are advised to update to version 26.5 of their respective operating systems to resolve the issue.

Technical details

A null pointer dereference vulnerability exists in Apple's operating systems (iOS, iPadOS, macOS Tahoe, and tvOS) due to insufficient input validation. An attacker positioned on the same local network can exploit this flaw to trigger a denial-of-service (DoS) condition, leading to unexpected system termination or application crashes. The vulnerability was addressed by Apple in version 26.5 of the affected platforms through improved input validation mechanisms. No authentication or user interaction is explicitly required beyond network proximity.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched

References

Related threats