VDB
GCVE-110-NCSC-2026-266
GCVE-110-NCSC-2026-266
Advisory PublishedCVSS 5.7/10
Apple fixed an issue in iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6 that allowed apps to improperly access user contact information by implementing enhanced verification checks.
Weaknesses (CWE)
CWE-522Insufficiently Protected CredentialsCWE-305Authentication Bypass by Primary WeaknessCWE-125Out-of-bounds ReadCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-416Use After FreeCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Risk Scores
CVSS 3.1
5.7/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Apple | vers:unknown/* | — | — |
Aliases
CVE-2026-28928CVE-2026-28931CVE-2026-28973CVE-2026-3783CVE-2026-3784CVE-2026-43673CVE-2026-43711CVE-2026-43714CVE-2026-43723CVE-2026-43729CVE-2026-43730CVE-2026-43733CVE-2026-43739CVE-2026-43740CVE-2026-43744CVE-2026-43753CVE-2026-43769CVE-2026-43776CVE-2026-43778CVE-2026-43780CVE-2026-43796CVE-2026-43797CVE-2026-43799CVE-2026-43800CVE-2026-43801CVE-2026-43803CVE-2026-43804CVE-2026-43805CVE-2026-43810CVE-2026-43811CVE-2026-43812CVE-2026-43813CVE-2026-43814CVE-2026-43816CVE-2026-43817CVE-2026-43818CVE-2026-43821CVE-2026-43822CVE-2026-4424CVE-2026-64692CVE-2026-64693CVE-2026-64700CVE-2026-64707CVE-2026-64709CVE-2026-64711CVE-2026-64713CVE-2026-64716CVE-2026-64718CVE-2026-64719CVE-2026-64720CVE-2026-64721CVE-2026-64722CVE-2026-64724CVE-2026-64725CVE-2026-64726CVE-2026-64728CVE-2026-64729CVE-2026-64730CVE-2026-64732CVE-2026-64733CVE-2026-64734CVE-2026-64735CVE-2026-64739CVE-2026-64740CVE-2026-64741CVE-2026-64742CVE-2026-64743CVE-2026-64746CVE-2026-64747CVE-2026-64749CVE-2026-64751CVE-2026-64754CVE-2026-64755CVE-2026-64757CVE-2026-64758CVE-2026-64763CVE-2026-64764CVE-2026-64765CVE-2026-64766CVE-2026-64768CVE-2026-64769CVE-2026-64770CVE-2026-64771CVE-2026-64772CVE-2026-64774CVE-2026-64775CVE-2026-64783
References
Browse GCVE Records
76,019 records in the GCVE database · Updated August 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.