CVE-2026-28977
Description
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted file may lead to unexpected app termination.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds read in Apple's system components allows a malicious file to cause unexpected app termination; fixed in multiple OS updates.
CVE-2026-28977 is an out-of-bounds read vulnerability in Apple's operating systems. The bug resides in how the system handles file parsing; insufficient bounds checking can lead to reading beyond allocated memory. This issue affects iOS, iPadOS, macOS, tvOS, visionOS, and watchOS across various versions [1][2][3].
Exploitation requires an attacker to deliver a maliciously crafted file to the target device. The file can be processed by any application that handles the vulnerable file type, potentially without user interaction beyond opening or receiving the file. No special privileges or network position is needed, as the file could arrive via email, web download, or other means.
Successful exploitation causes unexpected app termination, resulting in a denial-of-service condition. The impact is limited to the app's process termination; there is no evidence of arbitrary code execution or data disclosure from the available sources.
Apple has addressed the vulnerability with improved bounds checking in the following updates: iOS 26.5 and iPadOS 26.5, iOS 18.7.9 and iPadOS 18.7.9, macOS Tahoe 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, tvOS 26.5, visionOS 26.5, and watchOS 26.5. Users are strongly advised to apply these patches to mitigate the risk.
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: 15.7.7
- Range: 18.7.9, 26.5
- Range: 18.7.9, 26.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- support.apple.com/en-us/127110nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127111nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127115nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127116nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127117nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127118nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127119nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127120nvdRelease NotesVendor Advisory
News mentions
1- Apple Patches Everything, (Mon, May 11th)SANS Internet Storm Center · May 11, 2026