Use After Free Vulnerability in Apple iOS, iPadOS, macOS, tvOS, and watchOS Products
CVE-2026-28994

5.3MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
11 May 2026

What is CVE-2026-28994?

A use after free vulnerability has been identified in various Apple products, affecting the memory management capabilities. An attacker with access to a privileged network may exploit this flaw to potentially execute a denial-of-service attack by transmitting specially crafted Wi-Fi packets, leading to an interruption of user services. Apple has addressed this issue in the latest updates, emphasizing the importance of keeping devices up-to-date to safeguard against such vulnerabilities.

Affected Version(s)

iOS and iPadOS 0 < 18.7.9

iOS and iPadOS 0 < 26.5

macOS 0 < 14.8.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.