An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to execute arbitrary code with kernel privileges.
History

Wed, 13 May 2026 05:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 21:45:00 +0000

Type Values Removed Values Added
Title Kernel Privilege Escalation via Out‑of‑Bounds Write in Apple iOS, iPadOS, and macOS

Tue, 12 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Mon, 11 May 2026 23:00:00 +0000

Type Values Removed Values Added
Title Kernel Privilege Escalation via Out‑of‑Bounds Write in Apple iOS, iPadOS, and macOS
Weaknesses CWE-122
CWE-787

Mon, 11 May 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 11 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to execute arbitrary code with kernel privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2026-05-11T20:08:27.702Z

Updated: 2026-05-13T03:57:43.156Z

Reserved: 2026-03-03T16:36:03.967Z

Link: CVE-2026-28819

cve-icon Vulnrichment

Updated: 2026-05-12T17:19:58.483Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-11T21:18:50.937

Modified: 2026-05-12T18:16:47.213

Link: CVE-2026-28819

cve-icon Redhat

No data.