VYPR
High severity8.8NVD Advisory· Published May 11, 2026· Updated Jun 17, 2026

CVE-2026-28995

CVE-2026-28995

Description

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • Apple Inc./Ipados2 versions
    cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <18.7.9
    • (no CPE)range: 18.7.9
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
    Range: <18.7.9
  • cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
    Range: >=26.0,<26.5
  • cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
    Range: <26.5
  • cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*range: <26.5
    • (no CPE)range: 26.5
  • cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*range: <26.5
    • (no CPE)range: 26.5
  • Apple Inc./tvOSllm-fuzzy
    Range: 26.5
  • Range: 26.5
  • Apple Inc./iOSllm-fuzzy
    Range: 18.7.9

Patches

Vulnerability mechanics

References

6

News mentions

1