CVE-2026-28958: Buffer Overflow
Accelerate. An out-of-bounds read was addressed with improved bounds checking.
Other sources
Accessibility. This issue was addressed through improved state management.
— Apple
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
AirDrop. A reachable assertion was addressed with improved input validation.
— Apple
APFS. A buffer overflow was addressed with improved bounds checking.
— Apple
APFS. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.7.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.5 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.7.10 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.7.10 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 26.5 - Configuration
Ensure the product uses HTTPS for sending information over the network.
Network communication Use HTTPS when sending information over the network = HTTPS - Configuration
Add an additional prompt requiring user consent, as described for this issue.
User consent flow Additional prompt for user consent = enabled
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-64732
- CVE-2026-43667
- CVE-2026-64695
- CVE-2026-43801
- CVE-2026-43776
- CVE-2026-64725
- CVE-2026-64747
- CVE-2026-64762
- CVE-2026-64707
- CVE-2026-43811
- CVE-2026-64746
- CVE-2026-64734
- CVE-2026-43797
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43711
- CVE-2026-43738
- CVE-2026-43802
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-43714
- CVE-2026-64742
- CVE-2026-64740
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-64716
- CVE-2026-28990
- CVE-2026-43661
- CVE-2026-43818
- CVE-2026-64693
- CVE-2026-39877
- CVE-2026-64760
- CVE-2026-64749
- CVE-2026-64744
- CVE-2026-43778
- CVE-2026-64735
- CVE-2026-43822
- CVE-2026-43799
- CVE-2026-64700
- CVE-2026-43724
- CVE-2026-43769
- CVE-2026-43722
- CVE-2026-64721
- CVE-2026-43809
- CVE-2026-43757
- CVE-2026-43754
- CVE-2026-64723
- CVE-2026-39868
- CVE-2026-43810
- CVE-2026-64709
- CVE-2026-4424
- CVE-2026-28973
- CVE-2026-64739
- CVE-2026-64743
- CVE-2026-64738
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-43807
- CVE-2026-43733
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64722
- CVE-2026-64768
- CVE-2026-64771
- CVE-2026-43812
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-43800
- CVE-2026-28996
- CVE-2026-43658
- CVE-2026-65338
- CVE-2026-43795
- CVE-2026-28984
- CVE-2026-28958
- CVE-2026-28947
- CVE-2026-43727
- CVE-2026-43735
- CVE-2026-39872
- CVE-2026-43663
- CVE-2026-65334
- CVE-2026-64757
- CVE-2026-64784
- CVE-2026-43676
- CVE-2026-65331
- CVE-2026-65335
- CVE-2026-65332
- CVE-2026-65333
- CVE-2026-65337
- CVE-2026-65336
- CVE-2026-65340
- CVE-2026-64781
- CVE-2026-64782
- CVE-2026-65341
- CVE-2026-64715
- CVE-2026-43734
- CVE-2026-43726
- CVE-2026-43699
- CVE-2026-43742
- CVE-2026-64780
- CVE-2026-43794
- CVE-2026-43725
- CVE-2026-43731
- CVE-2026-43705
- CVE-2026-43708
- CVE-2026-43700
- CVE-2026-43701
- CVE-2026-43745
- CVE-2026-43720
- CVE-2026-64778
- CVE-2026-43821
- CVE-2026-64779
- CVE-2026-43717
- CVE-2026-28979
- CVE-2026-64719
- CVE-2026-64726
- CVE-2026-64755
- CVE-2026-43660
- CVE-2026-28907
- CVE-2026-28962
- CVE-2026-28905
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28955
- CVE-2026-28903
- CVE-2026-28953
- CVE-2026-28902
- CVE-2026-28901
- CVE-2026-28913
- CVE-2026-28883
- CVE-2026-28917
- CVE-2026-28946
- CVE-2026-28942
- CVE-2026-28971
- CVE-2026-43670
- CVE-2026-28944
- CVE-2026-28991
- CVE-2026-28988
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-1837
- CVE-2026-28956
- CVE-2026-39869
- CVE-2026-28964
- CVE-2026-28936
- CVE-2026-28918
- CVE-2026-43659
- CVE-2026-28977
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-43655
- CVE-2026-43654
- CVE-2026-28897
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-43657
- CVE-2026-43653
- CVE-2026-28985
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28940
- CVE-2026-65367
- CVE-2026-28906
- CVE-2026-43656
- CVE-2026-28846
- CVE-2026-28963
- CVE-2026-28993
- CVE-2026-28974
- CVE-2026-28957
- CVE-2026-28994
- CVE-2026-28965
- CVE-2026-28920
- CVE-2026-28849
- CVE-2026-28922
- CVE-2026-28915
- CVE-2025-14017
- CVE-2025-14819
- CVE-2026-28923
- CVE-2026-28925
- CVE-2026-28978
- CVE-2026-28908
- CVE-2026-28954
- CVE-2026-28952
- CVE-2026-28900
- CVE-2026-28929
- CVE-2026-28941
- CVE-2026-28961
- CVE-2026-43652
- CVE-2026-39870
- CVE-2026-28848
- CVE-2026-28930
- CVE-2026-28919
- CVE-2026-28924
- CVE-2026-39871
- CVE-2026-28976
- CVE-2026-28819
- CVE-2026-28914
Frequently Asked Questions
What is the severity of CVE-2026-28958?
CVE-2026-28958 is considered a high-severity vulnerability due to potential out-of-bounds reads and buffer overflows.
How do I fix CVE-2026-28958?
To fix CVE-2026-28958, upgrade to the latest version of macOS Tahoe, iOS, iPadOS, visionOS, or Safari as specified.
What types of issues does CVE-2026-28958 address?
CVE-2026-28958 addresses out-of-bounds reads, permissions issues, and buffer overflows through improved bounds checking and additional restrictions.
Which Apple products are affected by CVE-2026-28958?
CVE-2026-28958 affects macOS Tahoe, iOS, iPadOS, visionOS, and Safari versions up to 26.5.
What are the potential impacts of CVE-2026-28958?
The potential impacts of CVE-2026-28958 include unauthorized access, data corruption, and potential control over vulnerable devices.