CVE-2026-28956General(apple / ipados)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-05-12); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-17: 1Mentions · 2026-05-19: 1Mentions · 2026-05-22: 1Mentions · 2026-06-06: 1Patch / Workaround · 2026-05-12: 105-1205-1705-1905-2206-06
Signal classification4 categories
General
240.0%
Patch
120.0%
Exploit
120.0%
Disclosure
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-05-171
General1
2026-05-191
Exploit1
2026-05-221
Disclosure1
2026-06-061
General1
Full discourse5 posts
  • impostor@impost0r_
    General

    New article at https://ret2p.lt/2025/05/17/AppleJPEGXL-CVE.html describing CVE-2026-28956 (vuln in AppleJPEGXL) Any constructive criticism is appreciated.

    Post summary

    The text merely references an external article about CVE-2026-28956 with no additional details.

    21621036920.4K
    2.3K followersView on X
  • impostor@impost0r_
    General

    Original scheduled payment: June. Now: July. Yeah; uh... what's going on, Apple? @AppleSupport (no clue if this'll help but hey; whatever). Re: ASB payout for CVE-2026-28956 for Apple Support I budgeted around this. Damn. https://t.co/XvsL5oWkEw

    Post summary

    The tweet mentions CVE‑2026‑28956 and refers to an ASB payout, but provides no technical details, PoC, exploit, patch or evidence of active exploitation.

    2002555.5K
    2.3K followersView on X
  • impostor@impost0r_
    Disclosure

    I was Googling my CVE and uh https://www.sentinelone.com/vulnerability-database/cve-2026-28956/ I laughed. @SentinelOne hi i found this vulnerability It affects macOS, iOS, anything using the library. Please refer to my article about the vulnerability on https://ref2p.lt (“Requiem”) to know more how this

    Post summary

    The user cited CVE‑2026‑28956 and linked to an article titled "Requiem," mentioning that it impacts macOS and iOS devices, but provided no exploitation, patch, or detailed vulnerability data.

    300641.2K
    2.3K followersView on X
  • BaconMania@BaconManiaGD
    Exploit

    @0xjohnny I gave claude sonnet a writeup on cve-2026-28956 and lara’s source code and now it’s getting code execution in a privileged process working (should work up to ios 26.2.1 in theory, likely excluding mte devices)

    Post summary

    The user reports progress in exploiting CVE-2026-28956 to achieve code execution on iOS 26.2.1, suggesting ongoing development of an exploitation method but without providing a full working exploit or PoC.

    00050661
    275 followersView on X
  • impostor📦‼️ | 👑💌@_impost3r_
    Patch

    @kylemsguy unpatched for now; but needs a chain stay on 26.4.x (CVE-2026-28956 might be able to do something in combo if you're creative enough; entitlements) it'd be funny as fuck though.

    Post summary

    The comment notes that CVE-2026-28956 is currently unpatched and recommends staying on version 26.4.x as a workaround, with no exploit or detailed vulnerability description provided.

    0000082
    294 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more