cbcvebase.
CVE-2026-28918
published 2026-05-11

CVE-2026-28918: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5…

PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.49%
38.7th percentile
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination.

Affected

8 ranges
VendorProductVersion rangeFixed in
appleios_and_ipados< 26.526.5
appleipados< 26.526.5
appleiphone_os< 26.526.5
applemacos< 26.526.5
applemacos>= 26.0 < 26.526.5
appletvos< 26.526.5
applevisionos< 26.526.5
applewatchos< 26.526.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.