CVE-2026-28941
HIGHiOS and iPadOS < 18.7.9 and macOS < 15.7.7 - Denial of Service and Memory Disclosure via Maliciously Crafted File
Title source: llmDescription
The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
References (3)
Core 3
Scores
CVSS v3
7.1
EPSS
0.0004
EPSS Percentile
11.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-119
Status
published
Products (6)
Apple/iOS and iPadOS
< 18.7.9
apple/ipados
< 18.7.9
apple/iphone_os
< 18.7.9
Apple/macOS
< 15.7.7
Apple/macOS
< 26.5
apple/macos
15.0 - 15.7.7
Published
May 11, 2026
Tracked Since
May 12, 2026