Memory Management Flaw in Apple Products
CVE-2026-28902

6.5MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
11 May 2026

What is CVE-2026-28902?

Apple has addressed a critical memory management flaw that could lead to unexpected process crashes when handling maliciously crafted web content. This vulnerability affects multiple versions of Apple’s operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. By improving memory handling, Apple has mitigated the risk associated with this issue, underscoring the importance of keeping systems updated to protect against potential exploits.

Affected Version(s)

iOS and iPadOS 0 < 26.5

macOS 0 < 26.5

Safari 0 < 26.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.