CVE-2026-28955: Apple Safari Web Inspector WebCore Style Resolver Use-After-Free Remote Code Execution Vulnerability
Accelerate. An out-of-bounds read was addressed with improved bounds checking.
Other sources
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
Accounts. An authorization issue was addressed with improved state management.
— Apple
AirDrop. A reachable assertion was addressed with improved input validation.
— Apple
APFS. A buffer overflow was addressed with improved bounds checking.
— Apple
App Intents. A logic issue was addressed with improved restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.7.9 - Upgrade
Upgrade
Apple Safari Web Inspector WebCore Style Resolverto a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 18.7.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 18.7.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Tahoe 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in tvOS 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in visionOS 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in watchOS 26.5 - Compensating control
Because user interaction is required to exploit this vulnerability (the target must visit a malicious page or open a malicious file), reduce exposure by avoiding navigation to untrusted web pages and opening untrusted files.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-43660
- CVE-2026-28907
- CVE-2026-28962
- CVE-2026-43658
- CVE-2026-28984
- CVE-2026-28905
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28955
- CVE-2026-28903
- CVE-2026-28953
- CVE-2026-28902
- CVE-2026-28901
- CVE-2026-28913
- CVE-2026-28883
- CVE-2026-28958
- CVE-2026-28917
- CVE-2026-28947
- CVE-2026-28946
- CVE-2026-28942
- CVE-2026-28971
- CVE-2026-43670
- CVE-2026-28944
- CVE-2026-28991
- CVE-2026-28988
- CVE-2026-43667
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-1837
- CVE-2026-28956
- CVE-2026-39869
- CVE-2026-28964
- CVE-2026-28936
- CVE-2026-28918
- CVE-2026-43659
- CVE-2026-43661
- CVE-2026-28977
- CVE-2026-28990
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-39877
- CVE-2026-43655
- CVE-2026-43654
- CVE-2026-28897
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-43657
- CVE-2026-43653
- CVE-2026-28985
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28940
- CVE-2026-65367
- CVE-2026-28906
- CVE-2026-43656
- CVE-2026-28846
- CVE-2026-28963
- CVE-2026-28993
- CVE-2026-28974
- CVE-2026-28957
- CVE-2026-28996
- CVE-2026-28994
- CVE-2026-28965
- CVE-2026-28920
- CVE-2026-28877
- CVE-2026-28872
- CVE-2026-28894
- CVE-2026-28870
- CVE-2026-28954
- CVE-2026-28952
- CVE-2026-28882
- CVE-2026-28929
- CVE-2026-28941
- CVE-2026-28873
- CVE-2026-28819
- CVE-2026-28849
- CVE-2026-28922
- CVE-2026-28915
- CVE-2025-14017
- CVE-2025-14819
- CVE-2026-28923
- CVE-2026-28925
- CVE-2026-28978
- CVE-2026-28908
- CVE-2026-28900
- CVE-2026-28961
- CVE-2026-43652
- CVE-2026-39870
- CVE-2026-28848
- CVE-2026-28930
- CVE-2026-28919
- CVE-2026-28924
- CVE-2026-39871
- CVE-2026-28976
- CVE-2026-28914
Frequently Asked Questions
What is the severity of CVE-2026-28955?
The severity of CVE-2026-28955 is considered high due to its potential to allow attackers to exploit multiple issues including out-of-bounds read, buffer overflow, and permission-related vulnerabilities.
How do I fix CVE-2026-28955?
To fix CVE-2026-28955, you must update your affected Apple devices to the latest software version, specifically version 26.5 or above.
What products are affected by CVE-2026-28955?
CVE-2026-28955 affects multiple Apple products including macOS Tahoe, iOS, iPadOS, visionOS, tvOS, and watchOS versions up to 26.5.
What types of vulnerabilities are addressed in CVE-2026-28955?
CVE-2026-28955 addresses vulnerabilities such as out-of-bounds reads, authorization issues, and buffer overflows.
Is CVE-2026-28955 present in older versions of Apple software?
Yes, CVE-2026-28955 is present in older software versions prior to 26.5 and 18.7.9 for specific products.