Junglewise Threat Intelligence

CVE-2026-28988: Apple Multiple Operating Systems privacy bypass in Accounts

CVE-2026-28988 · Severity: medium · CVSS 5.5 · Published 2026-05-11

Technologies: Apple macOS, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security flaw in Apple's operating systems could allow a malicious application to bypass privacy settings. This means an app might access information or perform actions that the user has specifically restricted in their privacy preferences. The issue affects iPhones, iPads, Macs, Apple Watches, and Vision Pro headsets.

Technical details

A permissions issue exists within the 'Accounts' component of multiple Apple operating systems. The vulnerability allows a locally installed application to bypass established Privacy preferences, potentially leading to unauthorized access to user account data or restricted system features. Apple addressed this by implementing additional restrictions and improved state management. The fix is available in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, and watchOS 26.5.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats