CVE-2026-28896

7.7

Apple · macOS, iOS, iPadOS, tvOS, visionOS, watchOS

A memory handling vulnerability in multiple Apple operating systems allows a local attacker to cause unexpected system termination or read sensitive kernel memory.

Executive summary

A memory handling flaw across the Apple ecosystem allows local attackers to bypass security boundaries to read kernel memory or crash the system.

Vulnerability

This is a memory handling vulnerability where an unauthenticated local attacker can trigger unauthorized kernel memory reads or cause a system crash through improper memory management.

Business impact

The ability to read kernel memory poses a severe risk to confidentiality, as it may expose sensitive data such as cryptographic keys, credentials, or session tokens residing in protected memory space. Additionally, the potential for system termination introduces an availability risk that could be leveraged for denial of service. Given the CVSS score of 7.7, this vulnerability represents a high-risk entry point for privilege escalation or lateral movement within an organization.

Remediation

Immediate Action: Apply the vendor-provided security updates for macOS, iOS, iPadOS, tvOS, visionOS, and watchOS to the versions listed above immediately.

Proactive Monitoring: Monitor system logs for repeated crash reports or unexpected kernel panics, which may indicate an attempt to exploit memory handling flaws.

Compensating Controls: Since this is a local exploit, strictly enforce device access policies, utilize full disk encryption, and ensure that untrusted applications are not executed on sensitive systems.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a clear risk to the integrity and confidentiality of Apple devices. Organizations should prioritize the deployment of the identified security patches across their fleet. Given the nature of kernel-level memory disclosure, delayed patching increases the window of opportunity for attackers to extract sensitive system information.

More Apple CVEs

Sources