CVE-2026-28988
Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An app may be able to bypass certain Privacy preferences.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A permissions issue in Apple operating systems allows an app to bypass Privacy preferences; patched in iOS 26.5, macOS Tahoe 26.5, visionOS 26.5, and watchOS 26.5.
Root
Cause
CVE-2026-28988 is a permissions issue in Apple's operating systems that was addressed with additional restrictions. The vulnerability allows an app to bypass certain Privacy preferences, potentially leaking sensitive user data or granting unauthorized access. The issue exists across multiple platforms including iOS, iPadOS, macOS, visionOS, and watchOS.
Exploitation
An attacker would need to persuade a user to run a malicious app on a vulnerable device. No special privileges are required beyond normal app execution. The vulnerability may be exploited remotely if the user installs a compromised application, untrusted application. The affected devices include iPhone 11 and later, specific iPad models, Macs running macOS Tahoe, Apple Vision Pro, and Apple Watch Series 6 and later [1][2][3][4].
Impact
If successfully exploited, a malicious app could bypass user-configured Privacy preferences, potentially gaining access to private information such as location data, contacts, photos, or microphone and camera feeds without the user's consent. This violates the user's explicit privacy settings and could lead to data leaks.
Mitigation
Apple has released patches for all affected platforms on May 11, 2026. Users are strongly recommended to update to iOS/iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, or watchOS 26.5 immediately to block this vulnerability. There are no known workarounds for unpatched systems.
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- support.apple.com/en-us/127110nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127115nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127119nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127120nvdRelease NotesVendor Advisory
News mentions
1- Apple Patches Everything, (Mon, May 11th)SANS Internet Storm Center · May 11, 2026