Improved Bounds Checks in Apple Products to Prevent Unexpected App Termination
CVE-2026-28977

6.2MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
11 May 2026

What is CVE-2026-28977?

CVE-2026-28977 is a vulnerability found in various Apple operating systems including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This flaw results from inadequate bounds checking, which can lead to unexpected app terminations when processing maliciously crafted files. The primary function of these systems is to provide a secure and user-friendly interface for Apple devices, and this vulnerability compromises that security. If exploited, it could negatively impact organizational operations by causing application failures, which may disrupt productivity and affect overall user experience.

Potential impact of CVE-2026-28977

  1. Application Crashes: Malicious actors could leverage this vulnerability to cause targeted applications to terminate unexpectedly, leading to loss of functionality and user trust.

  2. Data Loss: Unexpected terminations can result in users losing unsaved data, which could be detrimental for businesses that rely on continuous data entry and processing.

  3. Reduced System Availability: Frequent crashes can diminish system reliability, making it difficult for organizations to maintain consistent operations and potentially affecting service delivery to clients.

Affected Version(s)

iOS and iPadOS 0 < 18.7.9

iOS and iPadOS 0 < 26.5

macOS 0 < 14.8.7

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.