AI analysis
CVE-2026-28935 is a kernel memory-handling flaw affecting Apple's operating systems across iPhone, iPad, Mac, Apple TV, Apple Watch, and Apple Vision Pro. A malicious or compromised app running on an affected device may be able to corrupt kernel memory or cause unexpected system termination (crash/DoS), and kernel memory corruption issues of this class can potentially be leveraged to escape app sandboxing or elevate privileges, though Apple's advisory only confirms corruption and termination. Exploitation requires local code execution — an attacker must first get a victim to install and run a malicious app, or compromise an already-installed app. Apple addressed the issue with improved memory handling in iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of in-the-wild exploitation.
What to do: Patch all Apple devices promptly: iOS/iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27 (paired iPhone updates are required to update watchOS). Enable automatic updates and verify patch levels across managed device fleets via MDM. Because the flaw is triggered by a local app, restrict sideloading and untrusted third-party app sources and review recently installed apps for suspicious behavior until devices are patched.
Affected
| Apple iOS | Prior to 26.6.1 |
| Apple iPadOS | Prior to 26.6.1 |
| Apple macOS Sequoia | Prior to 15.8 |
| Apple macOS Tahoe | Prior to 26.6.2 |
| Apple tvOS | Prior to 27 |
| Apple visionOS | Prior to 27 |
| Apple watchOS | Prior to 27 |
Estimated exposure
massPotentially hundreds of millions to over 1 billion devices (Apple's ~2 billion active devices minus those already updated) — Apple's ecosystem comprises roughly 2 billion active devices running these operating systems, and every device not yet updated to the fixed releases remains exposed.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.