Improved Bounds Checks in Apple Products to Prevent Unexpected App Termination
CVE-2026-28977

6.2MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
11 May 2026

What is CVE-2026-28977?

This vulnerability arises from insufficient validation when processing specially crafted files, which may lead to unexpected termination of applications. Apple's security team has addressed this issue with improved bounds checks across multiple operating systems. Users are encouraged to update to the latest software versions to mitigate potential exploitation risks and enhance security posture.

Affected Version(s)

iOS and iPadOS 0 < 18.7.9

iOS and iPadOS 0 < 26.5

macOS 0 < 14.8.7

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.