CVE-2026-28953Patch(apple / ipados)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-16: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-16: 105-1205-16
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-05-161
Disclosure1
Full discourse2 posts
  • Maher Azzouzi@maherazz2
    Patch

    Apple fixed two vulnerabilities I reported affecting Safari/WebKit: CVE-2026-28953 and CVE-2026-28901. Sometimes mitigations can create new attack surfaces. https://support.apple.com/en-us/127110

    Post summary

    The author reports that Apple has fixed two Safari/WebKit vulnerabilities (CVE-2026-28953 & CVE-2026-28901) and points to an Apple support advisory for details.

    24041223.4K
    1.4K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-28953 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS up to 18.7.8/26.4 Web denial of service (WID-SEC-2026-1543) https://ift.tt/ufWcH3Z A vulnerability categorized as problematic has been discovered in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 18.7.8/…

    Post summary

    A denial‑of‑service vulnerability (CVE-2026-28953) affecting Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to versions 18.7.8/26.4 has been announced, with no mention of exploitation, patches or debunking.

    00000160
    974 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more