CVE-2026-28863

4 documents4 sources
Severity
6.5MEDIUM
EPSS
0.0%
top 92.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateApr 11

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to fingerprint the user.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5apple/tvos< 26.4
NVDapple/tvos< 26.4
NVDapple/ipados< 26.4
CVEListV5apple/watchos< 26.4
NVDapple/watchos< 26.4

🔴Vulnerability Details

2
CVEList
CVE-2026-28863: A permissions issue was addressed with additional restrictions2026-03-25
GHSA
GHSA-9q9v-gcpr-jqgv: A permissions issue was addressed with additional restrictions2026-03-25

💬Community

1
Bugzilla
CVE-2026-4152 gimp: GIMP: Remote Code Execution via malicious JP2 file parsing2026-04-11
CVE-2026-28863 (MEDIUM CVSS 6.5) | A permissions issue was addressed w | cvebase.io