CVE-2026-28990General(apple / ipados)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-12); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-25: 1Mentions · 2026-06-03: 1Mentions · 2026-09-28: 1Active Exploitation · 2026-06-03: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-06-03: 105-1205-2506-0309-28
Signal classification2 categories
General
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-121
General1
2026-05-251
General1
2026-06-031
Active Exploitation1
Full discourse4 posts
  • datalocaltmp@datalocaltmp

    Shout out to my Meta Red Team X colleagues for the fun of finding an EXR ImageIO bug in iOS 26.7 (CVE-2026-86869) - love it when you see a gallery crash on a Friday afternoon and hammer out a report together ❤️ Thanks @bellis1000 for the initial EXR write-up of CVE-2026-28990 - it directed us (and others it seems) to research the surface! tl;dr: bug was a linear oob write when rendering an EXR with a 4th alpha channel on an allocation meant for 3 channels.

    3150125557.3K
    1.7K followersView on X
  • Billy Ellis@bellis1000
    General

    It is unclear exactly which CVE this bug is as there are 3 for ImageIO in 26.5 https://support.apple.com/en-us/127110 Likely either CVE-2026-43661 or CVE-2026-28990

    Post summary

    The post expresses uncertainty about which of three CVEs applies to ImageIO 26.5, providing no technical or mitigation details.

    1101532.3K
    23.2K followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Apple iOS and other products (CVE-2026-28990) https://vuldb.com/vuln/362824

    Post summary

    The tweet notes a severity increase for CVE‑2026‑28990 affecting Apple iOS and other products, providing a link to a vulnerability database entry.

    0201085
    2.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-28990 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 1… EPSS 0.00 (15th pctl) ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-28990 #Apple #CyberSecurity #InfoSec

    Post summary

    CVE‑2026‑28990 is a high‑severity memory‑handling flaw that has already been exploited in the wild, and Apple has released fixes for the latest OS versions.

    00020276
    87 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more