CVE-2026-28952Disclosure(apple / ipados)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • Patch or workaround signal is available
  • 20 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 12 signals
  • Disclosure: 14 classified signals
  • General: 4 classified signals
  • Peaked 1d ago at 19 mentions (2026-05-26); latest day: 1
  • 20 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline20 mentions / 2d
05101419Mentions · 2026-05-26: 19Mentions · 2026-05-29: 1Patch / Workaround · 2026-05-26: 6Technical Details · 2026-05-26: 11Technical Details · 2026-05-29: 105-2605-29
Signal classification3 categories
Disclosure
1470.0%
General
420.0%
Patch
210.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-2619
Disclosure13General4Patch2
2026-05-291
Disclosure1
Full discourse20 posts
  • KK.aWSB@KKaWSB
    Disclosure

    Claude找出 macOS 内核洞,已经进 Apple 安全公告了。 macOS Tahoe 26.5 修了 CVE-2026-28952:Kernel 整数溢出,app 可导致系统异常终止,署名 Calif_io、Claude 和 Anthropic Research。 安全行业的分工在变:AI 不再只写 PoC,开始进漏洞署名栏。拐点在这一行。

    Post summary

    Apple announced the patch for CVE-2026-28952, a kernel integer overflow discovered by AI, but no exploit or active use in the wild is reported.

    6103288.6K
    89.1K followersView on X
  • 黄小木@ai_xiaomu
    Disclosure

    Apple 官方发布安全公告:CVE-2026-28952 macOS 26.5 内核漏洞——发现者是 Claude。 意思是: Anthropic 的 Claude 第一次以"独立漏洞研究员"身份被 Apple 记入安全公告。 AI 不只是给苹果写测试用例,是在替苹果找内核级别的漏洞: 这是 2026 年 AI 安全研究的分水岭事件。 对应的产业变化: 安全研究员这个职业,正在被 AI 部分替代。 但同时也被 AI 放大——会用 Claude 做安全研究的人,效率是 10 倍以上。 整个安全行业的"门槛"和"天花板"同时被改写。

    Post summary

    Apple announced CVE-2026-28952, a kernel vulnerability in macOS 26.5 discovered by Anthropic’s Claude. The incident highlights AI's growing role in uncovering security flaws.

    20010890
    33.9K followersView on X
  • mousepotato@iluciddreaming
    Disclosure

    Apple 刚发的安全公告,CVE-2026-28952,macOS 26.5 内核漏洞。 是 Claude 发现的。 不是"AI 辅助安全研究员发现"。是 AI 找到的。 顶尖安全研究员花职业生涯磨练的能力,AI 现在开始系统性地做了。

    Post summary

    Apple has released a security advisory for CVE-2026-28952, a macOS 26.5 kernel vulnerability, noting that it was found by AI.

    00011624
    5.9K followersView on X
  • Gen AI Spotlight@GenAISpotlight
    Disclosure

    🔍 𝗔𝗽𝗽𝗹𝗲 𝗖𝗿𝗲𝗱𝗶𝘁𝘀 𝗖𝗹𝗮𝘂𝗱𝗲 𝗳𝗼𝗿 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗧𝘄𝗼 𝗺𝗮𝗰𝗢𝗦 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀 Apple's macOS Tahoe 26.5 security update credits Claude and Anthropic for discovering two CVEs. CVE-2026-28952: an integer overflow found by http://Calif.io with Claude and Anthropic Research. CVE-2026-28942: a WebKit vulnerability found by Milad Nasr and Nicholas Carlini with Claude. Real-world proof that AI-assisted security research is producing results accepted by Apple. #Apple #Claude #Security #AI ─── 🤖 𝗙𝗼𝗿 𝗺𝗼𝗿𝗲 𝗔𝗜 𝗻𝗲𝘄𝘀 𝗮𝗻𝗱 𝘀𝘁𝗼𝗿𝘆 𝘀𝗼𝘂𝗿𝗰𝗲𝘀, 𝘀𝗲𝗮𝗿𝗰𝗵 "𝗚𝗲𝗻𝗔𝗜𝗦𝗽𝗼𝘁" 𝗼𝗻 𝗧𝗲𝗹𝗲𝗴𝗿𝗮𝗺

    Post summary

    Apple announced two new CVEs in macOS Tahoe discovered with AI, describing an integer overflow and a WebKit flaw, but no exploits, patches, or PoC were provided.

    0002099
    95 followersView on X
  • bento@dtk4723
    Disclosure

    apple credited claude for finding a kernel vuln in macos 26.5. CVE-2026-28952. like... the AI is writing its own cve entries now?? this is a different chapter

    Post summary

    Apple credited Claude, an AI model, for discovering a kernel vulnerability (CVE‑2026‑28952) in macOS 26.5, signifying a new chapter in AI involvement in vulnerability reporting.

    10010120
    674 followersView on X
  • AI Security Gateway@AISGateway
    Disclosure

    Also new: MiniMax M2.5 FP4 in the registry (pricing TBD). And @AnthropicAI's Claude independently found CVE-2026-28952 a macOS 26.5 kernel vuln. AI finding zero-days is no longer theoretical.🔬

    Post summary

    Anthropic AI’s Claude discovered a new macOS 26.5 kernel vulnerability, CVE-2026-28952, and disclosed it. No exploitation details, patches, or PoC information are provided.

    1000077
    39 followersView on X
  • AI Security Gateway@AISGateway
    General

    The same AI capability that found CVE-2026-28952 is being used inside your org right now, by developers, security engineers, researchers. With a gateway layer, you can see exactly what's being sent to those models before it leaves your perimeter. Visibility first.📊

    Post summary

    The post highlights an AI tool used internally to detect CVE-2026-28952 and monitor model traffic, but it offers no exploit details, patches, or technical depth.

    1000035
    40 followersView on X
  • B Devanarayanan@devanarayanan_b
    Disclosure

    1/ Claude discovered CVE-2026-28952, a kernel vulnerability in macOS 26.5 now patched by Apple First time an LLM has found a production OS kernel vuln that made it into official security advisories, sets the bar for what automated code review can catch.

    Post summary

    A new kernel CVE (CVE-2026-28952) was discovered by Claude in macOS 26.5 and has already been patched by Apple, marking the first production OS kernel vulnerability found by an LLM.

    1000080
    8 followersView on X
  • B Devanarayanan@devanarayanan_b
    General

    Claude found CVE-2026-28952, a macOS 26.5 kernel vuln. Google beats OpenAI's math breakthrough 9 to 1. Pope Leo XIV's AI encyclical drops. 2026-05-26. Thread 🧵

    Post summary

    The post only notes the existence of CVE-2026-28952 as a macOS 26.5 kernel vulnerability, without further technical detail or actionable information.

    1000088
    8 followersView on X
  • Thomas Oomens@HonestDevIO
    Disclosure

    Claude found a macOS kernel vulnerability. CVE-2026-28952, credited on Apple's official security page. We debated for years whether AI would be used to attack or defend. The defenders got there first. Security researchers: what's your LLM-assisted workflow right now?

    Post summary

    Claude reported a new macOS kernel vulnerability (CVE‑2026‑28952) that Apple has documented on its official security page, indicating a recent disclosure with no exploit or patch details provided.

    00010121
    86 followersView on X
  • The Agent Times@TheAgentTimes
    Patch

    Apple's macOS Tahoe 26.5 patch credits http://Calif.io, Claude, and Anthropic Research for discovering CVE-2026-28952, a kernel privilege escalation vulnerability on M5 Macs — believed to be the first time an AI model has been named in an Apple security bulletin. https://t.co/6M9u5VISUP

    Post summary

    Apple released macOS Tahoe 26.5 to address CVE‑2026‑28952, a kernel privilege escalation flaw on M5 Macs, crediting AI research for the discovery.

    10000140
    165 followersView on X
  • Skewbed@skewbed
    General

    @lostbutlucky Was it CVE-2026-28952?

    Post summary

    The tweet merely asks if a specific CVE is the relevant vulnerability, with no additional information.

    0001068
    106 followersView on X
  • Hacker News 20@betterhn20
    Disclosure

    CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude https://support.apple.com/en-us/127115 (https://news.ycombinator.com/item?id=48273169)

    Post summary

    Apple identified a kernel vulnerability (CVE‑2026‑28952) in macOS 26.5, with a link to the vendor advisory available.

    10000111
    3.0K followersView on X
  • TechPulseHK@TechPulseHK
    General

    Apple 安全更新首次致謝 AI。唔係工程師,係 Claude。 CVE-2026-28952 借助 Claude 發現,Apple 安全文件直接致謝 Anthropic。繼逾兩萬漏洞掃出後,AI 協助安全研究正式有官方紀錄。 由「Mythos 太危險」到「Apple 致謝」,幾個月完成反轉。 #AI #ClaudeAI #TechPulseHK https://news.google.com/rss/articles/CBMicEFVX3lxTFBDdlNLWlRBeFM2TFlReGhpUFpnOWNjNE50RDNpcUtSaldEMDlOcHNsM0Itb2RVT0RRTC1MNkljei1YaVhQanhreUVLRkNCUWhkRk9vVm0wc2hMS05DSktqNkpxR3NETEd0MW1PX0JzaFM Score: 72/100 reviewed: false

    Post summary

    The article reports that CVE‑2026‑28952 was identified with the help of Anthropic’s Claude AI and that Apple’s security documentation now expressly thanks the AI tool, marking the first official acknowledgment of AI assistance in vulnerability discovery.

    0000089
    20 followersView on X
  • La Gazette IA@LaGazetteIA
    Disclosure

    CVE-2026-28952 : Claude crédité pour une faille noyau APFS de macOS 26.5 corrigée le 11 mai 2026. Une IA nommée dans un advisory Apple. http://lagazetteia.fr/ia-generale/cve-2026-28952-claude-decouvre-une-faille-critique-du-noyau/ #IA #Cybersecurite #macOS

    Post summary

    Apple announced CVE-2026-28952, a kernel-level APFS vulnerability in macOS 26.5 discovered by the AI Claude, and released a patch on May 11, 2026.

    0000064
    11 followersView on X
  • KI-Schild@KIShieldGermany
    Disclosure

    Claude findet kritische macOS-Lücke in Stunden -- Menschen hätten Wochen gebraucht. CVE-2026-28952 ermöglicht komplette Systemkontrolle. KI revolutioniert Cybersecurity. Aber Kriminelle nutzen dieselbe Technologie.

    Post summary

    AI‑powered tool Claude rapidly identified a critical macOS vulnerability, CVE‑2026‑28952, that potentially permits full system compromise, while noting that criminals are leveraging similar technologies.

    0000067
    1 followersView on X
  • (((JReuben1)))@jreuben1
    Patch

    CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude https://support.apple.com/en-us/127115

    Post summary

    Apple’s support article for CVE-2026-28952 indicates a kernel vulnerability in macOS 26.5 with a patch or mitigation available, but it does not mention PoC, exploits, or active exploitation.

    00000106
    2.1K followersView on X
  • Hacker News 50@betterhn50
    Disclosure

    CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude https://support.apple.com/en-us/127115 (https://news.ycombinator.com/item?id=48273169)

    Post summary

    A new macOS kernel vulnerability (CVE-2026-28952) was discovered by Claude, and Apple has issued a support advisory that likely contains patch or remediation details.

    00000133
    2.1K followersView on X
  • Tech Daily 24/7@techdaily24
    Disclosure

    CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude https://support.apple.com/en-us/127115 #TechNews #startups

    Post summary

    The post announces the discovery of CVE-2026-28952, a kernel vulnerability in macOS 26.5, and provides a link to an Apple support page.

    0000050
    86 followersView on X
  • Xavier Rivera@XavierRiveraX
    Disclosure

    Apple's macOS Tahoe 26.5 security notes credit Claude and Anthropic Research for two CVEs: a kernel integer overflow (CVE-2026-28952) and a WebKit use-after-free (CVE-2026-28942). An AI model is now officially credited in Apple's OS security release.

    Post summary

    Apple’s macOS security notes credit AI research for discovering two CVEs—a kernel integer overflow and a WebKit use‑after‑free—underscoring the growing role of AI in vulnerability identification.

    00000129
    563 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more