CVE-2026-28995Patch(apple / ipados)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-19); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-19: 1Mentions · 2026-06-05: 1Mentions · 2026-07-03: 1Active Exploitation · 2026-07-03: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-05-19: 105-1906-0507-03
Signal classification3 categories
Patch
133.3%
General
133.3%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-191
Patch1
2026-06-051
General1
2026-07-031
Active Exploitation1
Full discourse3 posts
  • ፀኒሃ🇪🇹🇺🇸🇵🇸@Tsenihas
    General

    Federal vulnerability record CVE-2026-28995

    Post summary

    The content merely lists a CVE identifier without providing any additional context or details.

    0001065
    13 followersView on X
  • vamx@feltcalm
    Patch

    Got my first CVE, and it happens to be with Apple. Discovered an improper privilege management flaw in App Intents (CVE-2026-28995). It grants a full sandbox escape and even bypasses Lockdown Mode, it was a fun challenge. CVSS 8.8. Fix is live across the ecosystem. Update to 26.5. Advisory: https://support.apple.com/en-us/127110 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-28995

    Post summary

    Apple has disclosed CVE-2026-28995, a privilege‑management flaw allowing sandbox escape and Lockdown bypass, with a CVSS of 8.8, and released a patch in update 26.5.

    10000105
    7 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-28995 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 a… EPSS 0.00 (2th pctl) ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-28995 #Apple #CyberSecurity #InfoSec

    Post summary

    CVE‑2026‑28995 is a logic vulnerability addressed by iOS 18.7.9 / iPadOS 18.7.9; reports confirm it is being exploited in the wild.

    00000174
    84 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more