CVE-2026-28819Patch(apple / ipados)

MEDIUMCVSS 5.4 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to execute arbitrary code with kernel privileges.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 2d ago at 1 mentions (2026-05-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-18: 1Mentions · 2026-05-26: 1Active Exploitation · 2026-05-12: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-26: 105-1205-1805-26
Signal classification2 categories
Patch
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-121
Active Exploitation1
2026-05-181
Patch1
2026-05-261
Patch1
Full discourse3 posts
  • PatchDay Alert@patchdayalert
    Patch

    CVE-2026-28819 is a macOS Wi-Fi kernel bug. Aggregators are reaching for Broadpwn comparisons. Apple's own wording says local-app trigger, not rogue access point. Patch on a 72-hour DDM clock, not a panic clock. https://patchdayalert.com/blog/macos-wifi-cve-2026-28819-not-broadpwn/?utm_source=twitter&utm_medium=social&utm_campaign=manual-drip&utm_content=macos-wifi

    Post summary

    Apple’s patch for CVE‑2026‑28819 addresses a macOS Wi‑Fi kernel bug described as a local‑app trigger rather than a rogue AP attack, with no PoC or active exploitation reported.

    0001088
    47 followersView on X
  • su8 / denchu@__su888
    Patch

    macOS Tahoe 26.5が2026年5月11日にリリース。Wi-Fiのカーネル権限任意コード実行(CVE-2026-28819)、CUPSのroot昇格、Gatekeeperバイパス等を修正。ClaudeとAnthropic協力でカーネル/WebKitの脆弱性も発見された / About the security content of macOS Tahoe 26.5 https://support.apple.com/en-us/127115

    Post summary

    Apple released macOS Tahoe 26.5 with fixes for several vulnerabilities, including CVE-2026-28819, along with root escalation and Gatekeeper bypass fixes, as announced via the Apple support page.

    00000154
    792 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploiting CVE-2026-28819 can escalate from app-level compromise to kernel privileges, then pivot laterally within systems. This Wi-Fi component vulnerability demonstrates how kernel-level access enables post-compromise movement across network segments. #ZeroDay 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/apple-may-2026-security-update-cve-2026-28819

    Post summary

    Attackers are actively using CVE‑2026‑28819 to grow from application‑level access to kernel privileges, enabling lateral movement across network segments.

    0000037
    1.9K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more