Logic Issue in Apple iOS and macOS Products
CVE-2026-28995

8.8HIGH

Key Information:

Vendor

Apple

Vendor
CVE Published:
11 May 2026

What is CVE-2026-28995?

A logic issue has been identified in Apple’s operating systems that could potentially allow a malicious application to escape its assigned sandbox environment. This flaw was rectified with enhanced restrictions in various versions of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Users are encouraged to update their devices to the latest versions to mitigate any risks associated with this vulnerability. The fixed versions include iOS 18.7.9, iPadOS 18.7.9, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.

Affected Version(s)

iOS and iPadOS 0 < 18.7.9

iOS and iPadOS 0 < 26.5

macOS 0 < 26.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.