Input Validation Flaw in Apple’s iOS and macOS Products
CVE-2026-28985

Currently unrated

Key Information:

Vendor

Apple

Vendor
CVE Published:
11 May 2026

What is CVE-2026-28985?

A vulnerability exists in Apple's iOS, iPadOS, macOS, and tvOS due to improper input validation, leading to a null pointer dereference. An attacker on the local network could exploit this flaw to induce a denial-of-service condition. The issue has been remedied in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, and tvOS 26.5, enhancing the security of these platforms.

Affected Version(s)

iOS and iPadOS 0 < 26.5

macOS 0 < 26.5

tvOS 0 < 26.5

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.