CVE-2026-28960
massRemote Denial-of-Service in Apple iOS and iPadOS (Fixed in 18.7.10)
CVE-2026-28960 is an improper input validation flaw (CWE-20) in Apple iOS and iPadOS that allows a remote attacker to cause a denial of service, meaning an affected device or service can be crashed or made unavailable. With a CVSS 3.1 base score of 7.5 (network vector, low attack complexity, no privileges or user interaction required), the flaw can plausibly be triggered remotely by supplying maliciously crafted input that the vulnerable component fails to validate before processing. The impact is limited to availability — there is no indication of confidentiality or integrity compromise. The issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, so any iPhone or iPad running an earlier version of these operating system lines is potentially exposed. No public proof-of-concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.
What to do: Update affected iPhones and iPads to iOS 18.7.10 or iPadOS 18.7.10 (or later) as soon as possible, prioritizing any devices that are network-reachable or in high-value deployments. Because this is a denial-of-service-only flaw with no confidentiality or integrity impact, patch urgency is moderate, but administrators should still push the update via MDM and verify completion. Watch for unexplained application crashes, device reboots, or hangs as possible indicators of abuse until patching is complete.
| Apple iOS | prior to 18.7.10 (fixed in iOS 18.7.10) |
| Apple iPadOS | prior to 18.7.10 (fixed in iPadOS 18.7.10) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.
- Vendors
- apple
- Products
- ipados, iphone os
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.