High severity7.5NVD Advisory· Published Mar 25, 2026· Updated Jun 17, 2026
CVE-2026-28894
CVE-2026-28894
Description
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A remote attacker may be able to cause a denial-of-service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <26.4
- (no CPE)range: before 26.4
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: >=14.0,<14.8.5
- (no CPE)range: 0
- Range: before 15.7.5
- Range: before 14.8.5
- Range: before 26.4
- Range: before 26.4
- Range: 0
Patches
Vulnerability mechanics
References
4- support.apple.com/en-us/126792nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126794nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126795nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126796nvdRelease NotesVendor Advisory
News mentions
1- Apple Patches Everything, (Mon, May 11th)SANS Internet Storm Center · May 11, 2026