CVE-2026-28935

Apple · iOS, iPadOS, macOS, tvOS, visionOS, watchOS

A memory handling vulnerability in multiple Apple operating systems allows an application to cause unexpected system termination or kernel memory corruption.

Executive summary

An unauthenticated attacker can exploit a memory handling flaw across various Apple platforms to cause system crashes or corrupt kernel memory, posing a significant stability and security risk.

Vulnerability

This is a memory handling vulnerability that enables an application to induce unexpected system termination or corrupt kernel memory. According to the CVSS vector (AV:N/AC:L/PR:N/UI:N), the vulnerability is exploitable by an unauthenticated attacker without user interaction.

Business impact

Successful exploitation of this vulnerability can result in widespread system instability, service disruption, and potential kernel-level memory corruption. Given the CVSS score of 7.5, this high-severity flaw represents a substantial threat to organizational uptime and data integrity, as kernel corruption may lead to arbitrary code execution or total system compromise.

Remediation

Immediate Action: Apply the vendor-supplied security updates for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to the versions specified in the affected versions list immediately.

Proactive Monitoring: Monitor system logs for unexpected reboots, kernel panic reports, or abnormal application behavior that may indicate an attempt to trigger this memory corruption vulnerability.

Compensating Controls: While no direct virtual patch exists, maintain strict application sandboxing policies and limit the installation of untrusted software to reduce the attack surface available to malicious applications.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this vulnerability, combined with its potential for kernel-level impact, necessitates an immediate patching cycle across all affected Apple device fleets. Administrators should prioritize the deployment of the provided updates to eliminate the risk of system instability and potential exploitation before a proof-of-concept emerges.

More Apple CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources