CVE-2026-28876Disclosure(apple / ipados)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to access sensitive user data.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • visionos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacosvisionos

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-25: 2Mentions · 2026-04-04: 1Patch / Workaround · 2026-03-25: 103-2504-04
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-252
Disclosure1Patch1
2026-04-041
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-28876 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28876 #CVE-2026-28876 #CVE   #CyberSecurity #InfoSec https://t.co/3uD87CFwdG

    Post summary

    The tweet simply alerts to the existence of CVE-2026-28876, referencing its NVD page, but provides no technical, exploit, or mitigation details.

    0000043
    123 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Apple users, critical alert! A parsing flaw allows apps to access sensitive data 🚫. Update NOW to protect your privacy! 🛡️ iOS 18.7.7, macOS Sonoma 14.8.5, and more—check your devices! Stay secure! #Cybersecurity #Apple #DataProtection Read more: https://www.tenable.com/cve/CVE-2026-28876

    Post summary

    The tweet alerts iOS and macOS users to a parsing flaw that could expose sensitive data and urges updating to a patch, but offers no technical exploit or PoC details.

    0000099
    257 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28876 Path Traversal Vulnerability in Apple Operating Systems Allows Unauthorized Data Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28876

    Post summary

    The post announces a path traversal vulnerability in Apple operating systems that could lead to unauthorized data access, but provides no proof of concept, exploit code, or patch information.

    0000049
    4.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSapplevisionos---

Explore more