ZeroHour

CVE-2026-28935

mass

Kernel Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS

CVSS
EPSS
Published
()
Modified
AI analysis

CVE-2026-28935 is a kernel memory-handling flaw affecting Apple's operating systems across iPhone, iPad, Mac, Apple TV, Apple Watch, and Apple Vision Pro. A malicious or compromised app running on an affected device may be able to corrupt kernel memory or cause unexpected system termination (crash/DoS), and kernel memory corruption issues of this class can potentially be leveraged to escape app sandboxing or elevate privileges, though Apple's advisory only confirms corruption and termination. Exploitation requires local code execution — an attacker must first get a victim to install and run a malicious app, or compromise an already-installed app. Apple addressed the issue with improved memory handling in iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of in-the-wild exploitation.

What to do: Patch all Apple devices promptly: iOS/iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27 (paired iPhone updates are required to update watchOS). Enable automatic updates and verify patch levels across managed device fleets via MDM. Because the flaw is triggered by a local app, restrict sideloading and untrusted third-party app sources and review recently installed apps for suspicious behavior until devices are patched.

Affected
Apple iOSPrior to 26.6.1
Apple iPadOSPrior to 26.6.1
Apple macOS SequoiaPrior to 15.8
Apple macOS TahoePrior to 26.6.2
Apple tvOSPrior to 27
Apple visionOSPrior to 27
Apple watchOSPrior to 27
Estimated exposure
massPotentially hundreds of millions to over 1 billion devices (Apple's ~2 billion active devices minus those already updated) — Apple's ecosystem comprises roughly 2 billion active devices running these operating systems, and every device not yet updated to the fixed releases remains exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.