VYPR
Medium severity5.5NVD Advisory· Published May 11, 2026· Updated May 13, 2026

CVE-2026-28993

CVE-2026-28993

Description

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access user-sensitive data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authorization issue in Apple OS allowed apps to access sensitive user data without consent; fixed by adding an extra prompt.

Vulnerability

Details

CVE-2026-28993 addresses an authorization issue in Apple operating systems that could allow an app to access user-sensitive data without proper consent. The fix involves adding an additional prompt for user consent, ensuring that users are explicitly asked before sensitive data is accessed [1][2][3][4].

Impact

An app may be able to access user-sensitive data without the user's knowledge or consent, potentially leading to privacy breaches. The vulnerability affects multiple Apple platforms including iOS, iPadOS, macOS, and visionOS.

Mitigation

Apple has released updates for iOS 18.7.9/iPadOS 18.7.9, iOS 26.5/iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and visionOS 26.5. Users are advised to update to the latest versions to protect against this vulnerability [1][2][3][4].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

1