VDB

CVE-2026-28956

CVE-2026-28956 PUBLISHED CVSS 9.300000190734863 CRITICAL

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

Risk Scores

CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
ApplewatchOS0
ApplemacOS0, 0, 0
AppletvOS0
AppleiOS and iPadOS0
ApplevisionOS0

Timeline

  • May 11, 2026 CVE Published
  • May 12, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›