CVE-2026-28960: Security vulnerability
Published Sep 14, 2026
·Updated
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.7.10 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.7.10
Event History
Sep 14, 2026
CVE Published
via MITRE·08:52 PM
Data Sourced
via MITRE·08:52 PM
DescriptionWeakness
Frequently Asked Questions
1
Which systems need the update?
Systems running iOS or iPadOS should be updated to version 18.7.10, which contains the fix for this denial-of-service issue.
2
Does exploiting this issue require local access?
No. The available information states that a remote attacker may be able to cause a denial-of-service.
3
What can be done if the update cannot be installed immediately?
The provided information does not identify a workaround or mitigation other than installing iOS 18.7.10 or iPadOS 18.7.10.