Input Validation Vulnerability in Apple Products
CVE-2026-28907

Currently unrated

Key Information:

Vendor

Apple

Vendor
CVE Published:
11 May 2026

What is CVE-2026-28907?

A vulnerability has been identified in Apple operating systems that affects how input is validated. This flaw can lead to processing of maliciously crafted web content, potentially allowing exploitation of the Content Security Policy, which is essential for securing web applications. Apple has addressed this issue in various software updates, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions, by implementing improved input validation techniques.

Affected Version(s)

iOS and iPadOS 0 < 18.7.9

iOS and iPadOS 0 < 26.5

macOS 0 < 26.5

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.