CVE-2026-28877

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

11 May 2026, 21:18

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/126796 -
  • () https://support.apple.com/en-us/127111 -
Summary (en) An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data. (en) An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.

26 Mar 2026, 20:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
Summary
  • (es) Un problema de autorización se abordó con una gestión de estado mejorada. Este problema está solucionado en iOS 26.4 y iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. Una aplicación podría acceder a datos sensibles del usuario.
CPE cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
First Time Apple watchos
Apple iphone Os
Apple visionos
Apple ipados
Apple
Apple macos
CWE CWE-200
NVD-CWE-noinfo
References () https://support.apple.com/en-us/126792 - () https://support.apple.com/en-us/126792 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/126794 - () https://support.apple.com/en-us/126794 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/126795 - () https://support.apple.com/en-us/126795 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/126798 - () https://support.apple.com/en-us/126798 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/126799 - () https://support.apple.com/en-us/126799 - Release Notes, Vendor Advisory

25 Mar 2026, 01:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 01:17

Updated : 2026-05-11 21:18


NVD link : CVE-2026-28877

Mitre link : CVE-2026-28877

CVE.ORG link : CVE-2026-28877


JSON object : View

Products Affected

apple

  • ipados
  • watchos
  • visionos
  • macos
  • iphone_os
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor