VYPR
Medium severity5.5NVD Advisory· Published May 11, 2026· Updated May 13, 2026

CVE-2026-28988

CVE-2026-28988

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An app may be able to bypass certain Privacy preferences.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A permissions issue in Apple operating systems allows an app to bypass Privacy preferences; patched in iOS 26.5, macOS Tahoe 26.5, visionOS 26.5, and watchOS 26.5.

Root

Cause

CVE-2026-28988 is a permissions issue in Apple's operating systems that was addressed with additional restrictions. The vulnerability allows an app to bypass certain Privacy preferences, potentially leaking sensitive user data or granting unauthorized access. The issue exists across multiple platforms including iOS, iPadOS, macOS, visionOS, and watchOS.

Exploitation

An attacker would need to persuade a user to run a malicious app on a vulnerable device. No special privileges are required beyond normal app execution. The vulnerability may be exploited remotely if the user installs a compromised application, untrusted application. The affected devices include iPhone 11 and later, specific iPad models, Macs running macOS Tahoe, Apple Vision Pro, and Apple Watch Series 6 and later [1][2][3][4].

Impact

If successfully exploited, a malicious app could bypass user-configured Privacy preferences, potentially gaining access to private information such as location data, contacts, photos, or microphone and camera feeds without the user's consent. This violates the user's explicit privacy settings and could lead to data leaks.

Mitigation

Apple has released patches for all affected platforms on May 11, 2026. Users are strongly recommended to update to iOS/iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, or watchOS 26.5 immediately to block this vulnerability. There are no known workarounds for unpatched systems.

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

1