CVE-2026-28942Disclosure(apple / ipados)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-26)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-11: 1Mentions · 2026-05-16: 1Mentions · 2026-05-26: 2Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-26: 205-1105-1605-26
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-111
General1
2026-05-161
Disclosure1
2026-05-262
Disclosure2
Full discourse4 posts
  • High Flyer@PineFlyer
    General

    @MacRumors Interestingly enough, this fix was attributed to Claude CVE-2026-28942: Milad Nasr and Nicholas Carlini with Claude, Anthropic

    Post summary

    The tweet notes that a fix for CVE-2026-28942 is attributed to Claude, but offers no technical details or actionable information.

    00030718
    165 followersView on X
  • Gen AI Spotlight@GenAISpotlight
    Disclosure

    🔍 𝗔𝗽𝗽𝗹𝗲 𝗖𝗿𝗲𝗱𝗶𝘁𝘀 𝗖𝗹𝗮𝘂𝗱𝗲 𝗳𝗼𝗿 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗧𝘄𝗼 𝗺𝗮𝗰𝗢𝗦 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀 Apple's macOS Tahoe 26.5 security update credits Claude and Anthropic for discovering two CVEs. CVE-2026-28952: an integer overflow found by http://Calif.io with Claude and Anthropic Research. CVE-2026-28942: a WebKit vulnerability found by Milad Nasr and Nicholas Carlini with Claude. Real-world proof that AI-assisted security research is producing results accepted by Apple. #Apple #Claude #Security #AI ─── 🤖 𝗙𝗼𝗿 𝗺𝗼𝗿𝗲 𝗔𝗜 𝗻𝗲𝘄𝘀 𝗮𝗻𝗱 𝘀𝘁𝗼𝗿𝘆 𝘀𝗼𝘂𝗿𝗰𝗲𝘀, 𝘀𝗲𝗮𝗿𝗰𝗵 "𝗚𝗲𝗻𝗔𝗜𝗦𝗽𝗼𝘁" 𝗼𝗻 𝗧𝗲𝗹𝗲𝗴𝗿𝗮𝗺

    Post summary

    Apple credits AI-assisted research for discovering two CVEs—an integer overflow and a WebKit flaw—in macOS, but offers no details about exploits, patches, or current active use.

    0002099
    95 followersView on X
  • Xavier Rivera@XavierRiveraX
    Disclosure

    Apple's macOS Tahoe 26.5 security notes credit Claude and Anthropic Research for two CVEs: a kernel integer overflow (CVE-2026-28952) and a WebKit use-after-free (CVE-2026-28942). An AI model is now officially credited in Apple's OS security release.

    Post summary

    Apple’s macOS Tahoe 26.5 security release credits Claude and Anthropic Research for discovering and addressing two CVEs—a kernel integer overflow and a WebKit use‑after‑free—highlighting AI‑assisted vulnerability identification.

    00000129
    563 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-28942 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS up to 26.4 Web use after free (WID-SEC-2026-1543) https://ift.tt/8kOYCf1 A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 26.4 and classified as critical. Affected by this issu…

    Post summary

    Apple OS versions up to 26.4 are affected by a critical vulnerability (CVE‑2026‑28942), but no further exploitation details, patches, or PoC information are given.

    0000085
    974 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more