CVE-2026-28863General(apple / ipados)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to fingerprint the user.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • tvos
  • visionos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_ostvosvisionoswatchos

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-25: 1Mentions · 2026-04-15: 1Mentions · 2026-05-03: 1Patch / Workaround · 2026-05-03: 1Technical Details · 2026-05-03: 103-2504-1505-03
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-251
General1
2026-04-151
Disclosure1
2026-05-031
Patch1
Full discourse3 posts
  • Hedge Fund Manager@rich_hedge_fund
    Patch

    Available for: Apple Watch Series 6 and later:: An app may be able to fingerprint the user. A permissions bug was addressed with additional restrictions. CVE-2026-28863 Privacy attacks are getting way out of hand now.

    Post summary

    The text references CVE‑2026‑28863 impacting Apple Watch users, notes a permissions-based fingerprinting issue, and indicates that Apple has applied additional restrictions to mitigate the flaw.

    0000057
    170 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-28863 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28863 #CVE-2026-28863 #CVE   #CyberSecurity #InfoSec https://t.co/njj2JuDvyV

    Post summary

    The tweet announces a new CVE (2026‑28863) with unknown risk and product scope, pointing readers to the official NVD page for more information.

    0000024
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28863 User Privacy Bypass Vulnerability in Apple Operating Systems Before 26.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28863

    Post summary

    The text offers only a brief mention of CVE-2026-28863, labeling it as a user privacy bypass in Apple OS before 26.4, without any further technical, exploit, or patch details.

    0000045
    4.0K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more