|
31
|
7.5
-
|
HIGH
Network
|
A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.5 and iPadOS 26.5. A user may be able to view restricted content from the lock screen.
|
CWE-284
Improper Access Control
|
CVE-2026-28965
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
26.5
|
2026-05-13 03:46
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
7.5
-
|
HIGH
Network
|
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to access sensitive user data.
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-28964
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
26.5
|
2026-05-13 03:46
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
4.6
-
|
MEDIUM
Physics
|
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intelligence to access sensi…
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-28963
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
26.5
|
2026-05-13 23:35
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
7.5
-
|
HIGH
Network
|
This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing mal…
|
CWE-200
Information Exposure
|
CVE-2026-28962
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-14 06:16
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
7.5
-
|
HIGH
Network
|
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-28959
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-13 23:36
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
5.5
-
|
MEDIUM
Local
|
This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.
|
CWE-200
Information Exposure
|
CVE-2026-28958
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
26.5
|
2026-05-14 06:16
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
3.3
-
|
LOW
Local
|
An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to capt…
|
CWE-284
Improper Access Control
|
CVE-2026-28957
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-13 23:36
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
6.5
-
|
MEDIUM
Network
|
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, vision…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2026-28956
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
26.5
|
2026-05-13 23:08
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
7.5
-
|
HIGH
Network
|
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-28955
|
cpe:2.3:o:apple:iphone_os:*:*
|
26.0
|
|
|
18.7.9 26.5
|
2026-05-14 06:16
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
7.5
-
|
HIGH
Network
|
A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted …
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-28954
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
18.7.9
|
2026-05-13 02:21
2026-05-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|