CVE-2026-28877: Infoleak
802.1X. An authentication issue was addressed with improved state management.
Other sources
Accounts. An authorization issue was addressed with improved state management.
— Apple
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.7.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.8.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 18.7.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 18.7.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 26.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 26.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Sequoia 15.7.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Sonoma 14.8.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Tahoe 26.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in visionOS 26.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in watchOS 26.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28865
- CVE-2026-28877
- CVE-2026-28823
- CVE-2025-55753
- CVE-2025-58098
- CVE-2025-59775
- CVE-2025-65082
- CVE-2025-66200
- CVE-2026-28824
- CVE-2026-20696
- CVE-2026-20699
- CVE-2026-20684
- CVE-2026-20633
- CVE-2026-28910
- CVE-2026-28879
- CVE-2026-28822
- CVE-2026-28894
- CVE-2026-28866
- CVE-2026-20690
- CVE-2026-28821
- CVE-2026-28838
- CVE-2026-20679
- CVE-2026-28886
- CVE-2026-28878
- CVE-2026-28888
- CVE-2026-28893
- CVE-2025-14524
- CVE-2026-28876
- CVE-2026-28892
- CVE-2026-28926
- CVE-2026-28832
- CVE-2026-28870
- CVE-2026-28834
- CVE-2026-28881
- CVE-2026-28880
- CVE-2026-28833
- CVE-2025-64505
- CVE-2026-28842
- CVE-2026-28841
- CVE-2026-28868
- CVE-2026-28867
- CVE-2026-20698
- CVE-2026-20695
- CVE-2026-20687
- CVE-2026-28845
- CVE-2026-28882
- CVE-2026-20607
- CVE-2026-20692
- CVE-2026-20694
- CVE-2026-20632
- CVE-2026-28839
- CVE-2026-20701
- CVE-2026-28891
- CVE-2026-28827
- CVE-2026-28816
- CVE-2026-28826
- CVE-2026-20631
- CVE-2026-20693
- CVE-2026-28840
- CVE-2026-28862
- CVE-2026-28896
- CVE-2026-28831
- CVE-2026-28817
- CVE-2026-20688
- CVE-2026-28864
- CVE-2026-28830
- CVE-2026-28860
- CVE-2026-28835
- CVE-2026-28825
- CVE-2026-28818
- CVE-2026-20697
- CVE-2026-28820
- CVE-2026-28837
- CVE-2026-28844
- CVE-2026-28828
- CVE-2026-28852
- CVE-2026-20657
- CVE-2026-28829
- CVE-2026-20665
- CVE-2026-20643
- CVE-2026-28871
- CVE-2026-20664
- CVE-2026-28857
- CVE-2026-28861
- CVE-2026-28859
- CVE-2026-20691
- CVE-2026-28895
- CVE-2026-28874
- CVE-2026-28875
- CVE-2026-28872
- CVE-2026-28873
- CVE-2026-28863
- CVE-2026-28856
- CVE-2026-28858
- CVE-2026-28967
- CVE-2026-20637
- CVE-2026-20660
- CVE-2026-20639
- CVE-2026-20668
- CVE-2026-20651
- CVE-2026-43679
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-39869
- CVE-2026-28936
- CVE-2026-43659
- CVE-2026-28977
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-43654
- CVE-2026-28954
- CVE-2026-28897
- CVE-2026-28952
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-28929
- CVE-2026-43653
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28940
- CVE-2026-28941
- CVE-2026-65367
- CVE-2026-28906
- CVE-2026-43656
- CVE-2026-28846
- CVE-2026-28993
- CVE-2026-28957
- CVE-2026-28907
- CVE-2026-43660
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28903
- CVE-2026-28955
- CVE-2026-28953
- CVE-2026-28962
- CVE-2026-28917
- CVE-2026-43670
- CVE-2026-28819
- CVE-2026-28994
- CVE-2026-28920
Frequently Asked Questions
What is the severity of CVE-2026-28877?
CVE-2026-28877 has been classified as a critical vulnerability due to its impact on authentication and authorization.
How do I fix CVE-2026-28877?
To mitigate CVE-2026-28877, update your devices to iOS 26.4, iPadOS 26.4, macOS Sequoia 15.7.5, or other affected platforms as specified.
What devices are affected by CVE-2026-28877?
CVE-2026-28877 affects devices running iOS, iPadOS, macOS Tahoe, watchOS, and visionOS prior to the specified versions.
What types of issues does CVE-2026-28877 address?
CVE-2026-28877 addresses authentication and authorization issues stemming from insufficient state management.
Is there a workaround for CVE-2026-28877 before applying the update?
Currently, there are no recommended workarounds for CVE-2026-28877, and users are advised to apply the available updates promptly.