ZeroHour

CVE-2026-28968

mass

Out-of-Bounds Kernel Memory Write in Apple iOS, macOS, and watchOS Devices

CVSS
EPSS
Published
()
Modified
AI analysis

CVE-2026-28968 is an out-of-bounds write caused by insufficient bounds checking in Apple's platform software, addressed with improved checks in the broad September 2026 round of OS updates. A malicious or compromised app running on an affected device can trigger the flaw, resulting in unexpected system termination or corruption of kernel memory — an impact that typically signals crash/DoS potential and, in the worst case, a path toward privilege escalation or sandbox escape on Apple platforms. All unpatched iPhones and iPads (before iOS/iPadOS 26.7), Macs (macOS Sequoia before 15.8 and macOS Tahoe before 26.7), and Apple TV, Apple Watch, and Vision Pro devices on pre-27 builds of tvOS, watchOS, and visionOS are affected. Exploitation is local and app-triggered, so an attacker would first need to deliver a malicious app (for example via sideloading, abused enterprise certificates, or App Store review evasion) rather than attack remotely over the network. No public proof-of-concept exists, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported as of the advisory.

What to do: Deploy the September 2026 Apple updates as soon as possible: iOS/iPadOS 26.7 (or 27), macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. In managed fleets, use MDM to enforce minimum OS versions and audit patch compliance across all device types, since the fix shipped across every Apple platform simultaneously. Because the flaw is triggered by a locally running app, restrict sideloading and untrusted enterprise-signed or developer-signed apps on high-value devices to shrink the attack surface.

Affected
Apple iOSversions prior to 26.7 (fixed in iOS 26.7 and iOS 27)
Apple iPadOSversions prior to 26.7 (fixed in iPadOS 26.7 and iPadOS 27)
Apple macOS Sequoiaversions prior to 15.8 (fixed in 15.8)
Apple macOS Tahoeversions prior to 26.7 (fixed in 26.7)
Apple macOS Golden Gateversions prior to 27 (fixed in 27)
Apple tvOSversions prior to 27 (fixed in 27)
Apple visionOSversions prior to 27 (fixed in 27)
Apple watchOSversions prior to 27 (fixed in 27)
Estimated exposure
mass≈1–2 billion devices (Apple's global active installed base of iPhones, iPads, Macs, Apple Watches, Apple TVs, and Vision Pros prior to patching) — Apple has publicly reported well over 2 billion active devices in use worldwide, and virtually every unpatched iPhone, iPad, Mac, Apple TV, Apple Watch, and Vision Pro falls within the affected version ranges, so the pre-patch exposure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.