CVE-2026-28928
A use‑after‑free bug could let a malicious app crash Apple’s operating systems. The flaw was fixed in the 26.6 releases of iOS, iPadOS, macOS, tvOS, and watchOS. Updating to those or newer versions protects devices.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apple devices running iOS, iPadOS, macOS, tvOS, or watchOS before version 26.6 – iPhone, iPad, Mac, Apple TV, and Apple Watch users.
Real-world impact
An attacker could cause a targeted device to terminate unexpectedly, leading to a denial‑of‑service situation. The crash could be triggered by a malicious app or content without any user action.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited from the network, requires no privileges or user interaction, and can completely compromise the system by crashing it. The high impact on confidentiality, integrity, and availability justifies the critical rating.
What to do about it
- 01Upgrade your device to iOS 26.6 or later, iPadOS 26.6 or later, macOS Tahoe 26.6 or later, tvOS 26.6 or later, or watchOS 26.6 or later.
- 02Restart the device to ensure the update is applied.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- support.apple.com/en-us/128066release notesvendor advisory
- support.apple.com/en-us/128067release notesvendor advisory
- support.apple.com/en-us/128068release notesvendor advisory
- support.apple.com/en-us/128069release notesvendor advisory