CVE-2026-28969Disclosure(apple / ipados)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.7, macOS Sequoia 15.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, macOS Tahoe 26.7, tvOS 26.5, tvOS 27, visionOS 26.5, visionOS 27, watchOS 26.5, watchOS 27. An app may be able to cause unexpected system termination.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-12); latest day: 2
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-05-12: 4Mentions · 2026-05-20: 2Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 2Technical Details · 2026-05-20: 105-1205-20
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-124
Disclosure2General1Patch1
2026-05-202
Disclosure1General1
Full discourse6 posts
  • Ashish Kunwar@D0rkerDevil
    Patch

    Apple patched CVE-2026-28969, a use-after-free vulnerability in IOTimeSyncFamily / IOTimeSyncClockManager affecting iOS/iPadOS. Glad to be credited in Apple’s advisory alongside Mihalis Haatainen and Ari Hawking. #infosec #apple #cve https://t.co/7gV1Aq8RMa

    Post summary

    Apple has issued a patch for CVE‑2026‑28969, a use‑after‑free bug in IOTimeSync, with no reports of active exploitation.

    27050154.6K
    13.0K followersView on X
  • GanaSec@ganaseclabs
    Disclosure

    New blog from GanaSec: The 2017 Ghost in the Time Machine Hunting IOTimeSyncFamily on macOS Our Researcher Ashish Kunwar (@D0rkerDevil) independently discovered CVE-2026-28969 - a use-after-free race condition in Apple's IOTimeSyncFamily kernel extension.

    Post summary

    The text announces the discovery of CVE-2026-28969, a use‑after‑free race condition in macOS's IOTimeSyncFamily kernel extension, without any information on PoC, exploits, or patches.

    49030174.3K
    37 followersView on X
  • Het Mehta@hetmehtaa
    General

    Hunting IOTimeSyncFamily on macOS 26 | CVE-2026-28969 https://ganasec.com/blog/the-2017-ghost-in-the-time-machine-hunting-iotimesyncfamily https://t.co/6U96cLn99a

    Post summary

    The tweet merely announces hunting of IOTimeSyncFamily on macOS 26 referencing CVE-2026-28969 and posts a blog link, without providing technical or exploit details.

    0301761.7K
    42.2K followersView on X
  • Ashish Kunwar@D0rkerDevil
    General

    iokit said “free me” Apple said “CVE-2026-28969” 😭🍎

    Post summary

    The tweet merely references CVE-2026-28969 without additional context or details.

    0101111.4K
    13.0K followersView on X
  • GanaSec@ganaseclabs
    Disclosure

    Proud moment for GanaSec X Apple 🍎 Our researcher @D0rkerDevil responsibly disclosed a security vulnerability in Apple’s IOKit framework, contributing to a safer ecosystem through responsible security research. Acknowledged by Apple Security Team under CVE-2026-28969. https://t.co/bRgscKDCWs

    Post summary

    A responsible disclosure of CVE-2026-28969 was announced for Apple’s IOKit framework; Apple acknowledged the issue but no technical details or patch information were provided.

    001211.5K
    29 followersView on X
  • Bountyy Oy@BountyyOy
    Disclosure

    First blog is up. The 2017 Ghost. CVE-2026-28969. Kernel UAF in IOTimeSyncClockManagerUserClient. Same root cause as CVE-2017-13847. Patch got lost in a refactor and the bug came back. Eight years later. http://bountyy.fi/blog/the-2017-ghost #cve #apple #bugbounty

    Post summary

    The blog post reports the re‑emergence of kernel UAF CVE‑2026‑28969, noting it shares a root cause with an older CVE and that the patch was lost during refactoring.

    0000054
    3 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more