CVE-2026-28895General(apple / ipados)

LOWCVSS 4.6 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.

2.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-03-24); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
ipadosiphone_os

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-03-24: 2Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-03-28: 1Mentions · 2026-04-04: 1Mentions · 2026-07-30: 1PoC Mentioned / Linked · 2026-03-26: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-07-30: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-26: 1Technical Details · 2026-07-30: 103-2403-2503-2603-2804-0407-30
Signal classification4 categories
General
342.9%
Disclosure
228.6%
PoC
114.3%
Patch
114.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-242
Disclosure2
2026-03-251
General1
2026-03-261
PoC1
2026-03-281
General1
2026-04-041
General1
2026-07-301
Patch1
Full discourse7 posts
  •  Locos de manzanas @Juanky7274
    PoC

    🔒 **iOS 26.4**: más de 35 vulnerabilidades parcheadas. Lo más grave: - Bypass a la **Protección contra Robo de Dispositivos** (CVE-2026-28895) con solo el código. - Acceso al llavero por atacante local. - Fallos en privacidad de Mail y escapes de sandbox en WebKit. https://t.co/GqvyxbQHZJ

    Post summary

    The tweet announces that CVE‑2026‑28895 has been patched in iOS 26.4, provides technical details of the vulnerability, and indicates that a proof‑of‑concept exists, linking to a supporting article.

    0201411.4K
    2.4K followersView on X
  • ⋆。゚🪐。⋆。 ゚ℂ𝕃𝔸𝕌𝔻𝔼 & 𝔽ℝ𝕀𝔼ℕ𝔻𝕊 𝕀ℕℂ. 🛸 ⋆。゚☾@CLAUDEnFRIENDS
    Disclosure

    Apple credited Claude & Friends: Risk Analytics Research Group ⚠️🔬 (@CLAUDEnFRIENDs) in iOS 26.4 — CVE-2026-28895 (Stolen Device Protection bypass), Spotlight, and UIKit. cc @Apple @fantasyfootbll3 @claudeai @AnthropicAI $AAPL https://support.apple.com/en-us/126792#:~:text=Claude%20%26%20Friends%3A%20Risk%20Analytics%20Research%20Group%2C%20Zack%20Tickman%20for%20their%20assistance

    Post summary

    Apple announced CVE‑2026‑28895, a stolen device protection bypass, crediting the Claude & Friends research group; the post contains no PoC, exploit, patch, or active‑exploitation details.

    11032405
    3 followersView on X
  • Zack Tickman 🏀@fantasyfootbll3
    Disclosure

    Apple credited me + Claude & Friends: Risk Analytics Research Group ⚠️🔬 (@CLAUDEnFRIENDs) in iOS 26.4 — CVE-2026-28895 (Device Protection bypass), Spotlight, and UIKit. cc @Apple @CLAUDEnFRIENDS @claudeai @AnthropicAI $AAPL https://support.apple.com/en-us/126792#:~:text=CVE%2D2026%2D28895%3A%20Zack%20Tickman

    Post summary

    Apple has credited the Risk Analytics Research Group for discovering CVE‑2026‑28895, a device protection bypass affecting iOS 26.4’s Spotlight and UIKit components, and has provided a link to its support page for patch and advisory details.

    10022304
    808 followersView on X
  • Zack Tickman 🏀@zacktickman
    Patch

    CVE-2026-28895: a Stolen Device Protection bypass. Anyone holding your iPhone and your passcode could open your Face ID–locked apps, including Passwords. Credited across Apple's 26.4 security release — 11 credits over six advisories, spanning App Protection, Spotlight, and UIKit: iOS/iPadOS 26.4 — http://support.apple.com/en-us/126792 macOS Tahoe 26.4 — http://support.apple.com/en-us/126794 tvOS 26.4 — http://support.apple.com/en-us/126797 watchOS 26.4 — http://support.apple.com/en-us/126798 visionOS 26.4 — http://support.apple.com/en-us/126799 iOS/iPadOS 26.1 — http://support.apple.com/en-us/125632

    Post summary

    The post announces CVE‑2026‑28895 as a bypass of Stolen Device Protection, highlights Apple’s security patch releases, and provides links to advisories without describing active exploitation.

    10012246
    992 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-28895 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28895 #CVE-2026-28895 #CVE   #CyberSecurity #InfoSec https://t.co/McmilKhfWx

    Post summary

    The tweet announces a new CVE with minimal information and no technical, exploit, or mitigation details.

    0001038
    123 followersView on X
  • Nicolas Coolman@NicolasCoolman
    General

    ⚠️ Bulletin Apple 126801 : Faille Critique CVE-2026-28895 Contourne la Protection des Appareils Volés sur iOS ! (zoneantimalware) https://t.co/936VNpTfZ4

    Post summary

    The tweet alerts to a critical Apple vulnerability (CVE-2026-28895) but offers no PoC, exploit, patch, or technical specifics, remaining a general notice.

    0001060
    84 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28895 iOS Passcode Bypass Vulnerability in Stolen Device Protection Mechanism https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28895

    Post summary

    The text merely references CVE-2026-28895 with a title and a link, providing no actionable or detailed information.

    0000061
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---

Explore more