CVE-2026-28992

MEDIUM

iOS and iPadOS < 18.7.9 - Denial of Service via Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-28992. PoCs published by zeroxjf.

AI-analyzed exploit summary The repository contains functional exploit code demonstrating two race conditions in IOHIDFamily's FastPathUserClient, leading to kernel panics via UAF and AOP panic mechanisms. The PoCs leverage improper locking and entitlement checks to trigger memory corruption.

Description

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker may be able to cause unexpected app termination.

Exploits (1)

nomisec WORKING POC 8 stars
by zeroxjf · poc
https://github.com/zeroxjf/CVE-2026-28992-IOHIDFamily-FastPathUserClient-Race-Conditions

The repository contains functional exploit code demonstrating two race conditions in IOHIDFamily's FastPathUserClient, leading to kernel panics via UAF and AOP panic mechanisms. The PoCs leverage improper locking and entitlement checks to trigger memory corruption.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Complex
Reliability
Racy
Target: Apple IOHIDFamily (iOS 26.5 and iPadOS 26.5)
No auth needed
Prerequisites: iOS/iPadOS device with vulnerable IOHIDFamily kext · ability to run sandboxed app
devstral-2 · analyzed May 12, 2026 Full analysis →

Scores

CVSS v3 4.7
EPSS 0.0001
EPSS Percentile 2.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-362
Status published
Products (14)
Apple/iOS and iPadOS < 18.7.9
Apple/iOS and iPadOS < 26.5
apple/ipados < 18.7.9
apple/iphone_os < 18.7.9
Apple/macOS < 14.8.7
Apple/macOS < 15.7.7
Apple/macOS < 26.5
apple/macos 14.0 - 14.8.7
Apple/tvOS < 26.5
apple/tvos < 26.5
... and 4 more
Published May 11, 2026
Tracked Since May 12, 2026