Junglewise Threat Intelligence

CVE-2026-28994: Apple Multiple Operating Systems Use After Free in Wi-Fi Handling

CVE-2026-28994 · Severity: medium · CVSS 5.3 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability has been identified in several Apple operating systems, including iOS, macOS, and watchOS. An attacker located on the same Wi-Fi network as a target device could send specially crafted wireless packets to crash the system. This results in a denial-of-service, potentially disrupting business operations or personal use by forcing devices to restart or become unresponsive.

Technical details

A use-after-free vulnerability exists in multiple Apple operating systems due to improper memory management during the processing of Wi-Fi packets. An attacker in a privileged network position (adjacent/local network) can exploit this by transmitting specially crafted Wi-Fi packets to a vulnerable device. Successful exploitation leads to a denial-of-service (DoS) condition, typically manifesting as a system crash or unexpected termination. The issue was addressed by improving memory management logic across affected platforms, including iOS, iPadOS, macOS, tvOS, and watchOS.

Affected products

  • Apple iOS < 18.7.9, < 26.5
  • Apple iPadOS < 18.7.9, < 26.5
  • Apple macOS Sequoia < 15.7.7
  • Apple macOS Sonoma < 14.8.7
  • Apple macOS Tahoe < 26.5
  • Apple tvOS < 26.5
  • Apple watchOS < 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched

References

Related threats