CVE-2026-28867Patch(apple / ipados)

CRITICALCVSS 6.2 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to leak sensitive kernel state.

8.0/ 10 priority

Sources & remediation

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-05); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline10 mentions / 6d
01223Mentions · 2026-03-25: 2Mentions · 2026-03-29: 2Mentions · 2026-04-02: 1Mentions · 2026-04-15: 1Mentions · 2026-07-05: 3Mentions · 2026-07-26: 1PoC Mentioned / Linked · 2026-07-05: 2Exploit Tool / Code · 2026-07-05: 1Active Exploitation · 2026-07-05: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-29: 2Patch / Workaround · 2026-07-05: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-29: 2Technical Details · 2026-04-02: 103-2503-2904-0204-1507-0507-26
Signal classification5 categories
Patch
330.0%
General
220.0%
Disclosure
220.0%
PoC
220.0%
Active Exploitation
110.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-252
General1Patch1
2026-03-292
Patch2
2026-04-021
Disclosure1
2026-04-151
General1
2026-07-053
Active Exploitation1PoC2
2026-07-261
Disclosure1
Full discourse10 posts
  • Speedyfriend67@speedyfriend433
    PoC

    Here’s the PoC of CVE-2026-28867! Finally recovered from an old backup after 90 days of responsible disclosure.

    Post summary

    The post announces a Proof of Concept for CVE-2026-28867 following a 90‑day responsible disclosure, but provides no exploit code, patch, or technical details.

    220711411.3K
    2.6K followersView on X
  • Speedyfriend67@speedyfriend433
    Disclosure

    CVE-2026-28867 was also assigned to mDNSResponder by leaking TCP data in iOS 18.7.7. The same CVE got two different topics! https://t.co/0zDyiQA4Aq

    Post summary

    The tweet reports that CVE-2026-28867 is linked to mDNSResponder in iOS 18.7.7, noting that the CVE has multiple discussion topics but offers no PoC, exploits, or mitigation info.

    24056126.7K
    2.5K followersView on X
  • Speedyfriend67@speedyfriend433
    PoC

    https://github.com/speedyfriend433/CVE-2026-28867-PoC/blob/main/poc.c

    Post summary

    The content links to a GitHub repository that hosts a Proof of Concept (poc.c) for CVE‑2026‑28867, providing exploit code but no information about patches, active exploitation, or technical details.

    02029101.5K
    2.6K followersView on X
  • Speedyfriend67@speedyfriend433
    Disclosure

    @alencristen I just gave them my 3 Apple CVEs (CVE-2025-46280, CVE-2026-20654, CVE-2026-28867) and my GitHub profile for responsible disclosures

    Post summary

    The user indicates they have submitted three Apple CVEs for responsible disclosure and provided their GitHub profile for vendor contact.

    10010133
    2.6K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🍎 CVE-2026-28867 (Apple iOS/macOS/tvOS/watchOS 2026): App leaks sensitive kernel state; improved auth fixes. Patch all! https://nvd.nist.gov/vuln/detail/CVE-2026-28867

    Post summary

    The tweet announces CVE‑2026‑28867, notes a kernel‑state leak in Apple apps, and urges users across all Apple platforms to apply the patch.

    1000060
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🔴 CVE-2026-28867 (Apple iOS/macOS/tvOS up to recent): Improved auth fixes app sensitive data leak. Patch all Apple devices ASAP! https://nvd.nist.gov/vuln/detail/CVE-2026-28867

    Post summary

    Apple highlights a data‑leak vulnerability (CVE‑2026‑28867) affecting iOS/macOS/tvOS and urges users to apply patches immediately.

    1000061
    492 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-28867 This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 an… EPSS 0.00 (12th pctl) ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-28867 #Apple #CyberSecurity #InfoSec

    Post summary

    The post confirms that CVE‑2026‑28867 is actively exploited in the wild, is mitigated by recent OS releases, and provides a link to a detailed analysis, but offers no PoC, exploit code, or deep technical details.

    0000094
    84 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-28867 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28867 #CVE-2026-28867 #CVE   #CyberSecurity #InfoSec https://t.co/4u1JN40vxo

    Post summary

    The tweet announces a new CVE (CVE-2026-28867) with minimal details, lacking information on exploitation, technical specifics, or mitigation.

    0000023
    137 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Apple users, critical vulnerability CVE-2026-28867 exposed kernel state leaks! 🖥️ Update your devices NOW to prevent privilege escalation and deeper exploitation. Don’t risk your security! 🔒 Learn more here: https://www.tenable.com/cve/CVE-2026-28867 #CyberSecurity #AppleSecurity #InfoSec

    Post summary

    The tweet warns Apple users about CVE‑2026‑28867, a kernel state leak that could enable privilege escalation, and urges immediate system updates to mitigate the risk.

    0000054
    257 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28867 Kernel State Information Disclosure Vulnerability in Apple Operating Systems https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28867

    Post summary

    The announcement references CVE‑2026‑28867 as a kernel state information disclosure issue in Apple OS, but provides no additional technical details, PoC, or exploitation evidence.

    0000043
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more