
iOS 26.5 dropped today with a fix for CVE-2026-28994 — a Wi-Fi use-after-free our @defendtheworld discovered via automated Wi-Fi fuzzing. The bug is preauth and requires no user interaction.
Post summary
iOS 26.5 releases a fix for CVE‑2026‑28994, a pre‑authentication Wi‑Fi use‑after‑free vulnerability discovered via fuzzing, with no active exploitation or PoC noted.

