VDB
CVE-2026-28956
CVE-2026-28956
PUBLISHED
CVSS 9.300000190734863 CRITICAL
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | watchOS | 0 |
| Apple | macOS | 0, 0, 0 |
| Apple | tvOS | 0 |
| Apple | iOS and iPadOS | 0 |
| Apple | visionOS | 0 |
Timeline
- May 11, 2026 CVE Published
- May 12, 2026 Security Advisory
References
- https://support.apple.com/en-us/127110 url
- https://support.apple.com/en-us/127115 url
- https://support.apple.com/en-us/127116 url
- https://support.apple.com/en-us/127117 url
- https://support.apple.com/en-us/127118 url
- https://support.apple.com/en-us/127119 url
- https://support.apple.com/en-us/127120 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-28956 advisory
- https://support.apple.com/en-us/127114 advisory
- https://support.apple.com/en-us/127111 advisory
- https://support.apple.com/en-us/127113 advisory
- https://support.apple.com/en-us/127112 advisory