ZeroHour

CVE-2026-28960

mass

Remote Denial-of-Service in Apple iOS and iPadOS (Fixed in 18.7.10)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-28960 is an improper input validation flaw (CWE-20) in Apple iOS and iPadOS that allows a remote attacker to cause a denial of service, meaning an affected device or service can be crashed or made unavailable. With a CVSS 3.1 base score of 7.5 (network vector, low attack complexity, no privileges or user interaction required), the flaw can plausibly be triggered remotely by supplying maliciously crafted input that the vulnerable component fails to validate before processing. The impact is limited to availability — there is no indication of confidentiality or integrity compromise. The issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, so any iPhone or iPad running an earlier version of these operating system lines is potentially exposed. No public proof-of-concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.

What to do: Update affected iPhones and iPads to iOS 18.7.10 or iPadOS 18.7.10 (or later) as soon as possible, prioritizing any devices that are network-reachable or in high-value deployments. Because this is a denial-of-service-only flaw with no confidentiality or integrity impact, patch urgency is moderate, but administrators should still push the update via MDM and verify completion. Watch for unexplained application crashes, device reboots, or hangs as possible indicators of abuse until patching is complete.

Affected
Apple iOSprior to 18.7.10 (fixed in iOS 18.7.10)
Apple iPadOSprior to 18.7.10 (fixed in iPadOS 18.7.10)
Estimated exposure
massHundreds of millions of iPhone and iPad users worldwide running iOS/iPadOS versions prior to 18.7.10 — Apple's active installed base exceeds 1.5 billion iPhones alone, and every device not yet updated to iOS/iPadOS 18.7.10 remains vulnerable, so the affected population is plausibly in the hundreds of millions depending on patch adoption.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.

Vendors
apple
Products
ipados, iphone os
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.