|
21
|
7.5
-
|
HIGH
Network
|
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5,…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-28987
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-13 02:16
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
7.5
-
|
HIGH
Network
|
A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, …
|
CWE-362
Race Condition
|
CVE-2026-28986
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-13 02:16
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
6.2
-
|
MEDIUM
Local
|
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to …
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-28985
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
26.5
|
2026-05-13 23:08
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
7.5
-
|
HIGH
Network
|
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A r…
|
CWE-843
Type Confusion
|
CVE-2026-28983
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-13 23:22
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
6.2
-
|
MEDIUM
Local
|
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-28977
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-14 23:01
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
7.5
-
|
HIGH
Network
|
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watch…
|
CWE-284
Improper Access Control
|
CVE-2026-28974
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
26.5
|
2026-05-13 03:46
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
6.5
-
|
MEDIUM
Network
|
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, ma…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-28972
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-13 23:08
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
4.3
-
|
MEDIUM
Network
|
The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-28971
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
26.5
|
2026-05-14 06:16
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
7.5
-
|
HIGH
Network
|
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS T…
|
CWE-416
Use After Free
|
CVE-2026-28969
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-13 02:15
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
4.9
-
|
MEDIUM
Network
|
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4. An attacker in a privileged network position may…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-28967
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.7 26.4
|
2026-05-13 23:08
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|