PatchSiren cyber security CVE debrief
CVE-2026-28940 Apple CVE debrief
Apple addressed CVE-2026-28940 with improved memory handling. According to the official description, a maliciously crafted image may corrupt process memory. The issue is rated HIGH severity in the supplied NVD data and is mapped to CWE-119. Apple lists fixes across iOS, iPadOS, macOS, tvOS, and visionOS releases.
- Vendor
- Apple
- Product
- iOS and iPadOS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-11
- Original CVE updated
- 2026-05-13
- Advisory published
- 2026-05-11
- Advisory updated
- 2026-05-13
Who should care
Organizations and individuals running Apple devices that process untrusted images, especially fleet administrators managing iPhone, iPad, Mac, Apple TV, and Vision Pro devices. Security teams should prioritize systems exposed to email, messaging, web content, document workflows, or any application that renders external images.
Technical summary
The supplied corpus describes a memory-handling weakness in Apple image processing that can lead to process memory corruption when a maliciously crafted image is handled. NVD classifies the issue with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N and CWE-119. Apple states the issue is fixed in iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, and visionOS 26.5.
Defensive priority
High. The combination of network attack vector, no privileges required, no user interaction, and high confidentiality impact makes this a strong patching priority for internet-connected and user-facing Apple systems.
Recommended defensive actions
- Update affected Apple devices to the fixed releases listed in the Apple advisories: iOS 18.7.9 or 26.5, iPadOS 18.7.9 or 26.5, macOS Sequoia 15.7.7 or macOS Tahoe 26.5, tvOS 26.5, and visionOS 26.5.
- Prioritize devices that regularly process external images, including mail, messaging, browser, productivity, and media workflows.
- Use standard staged deployment and validation for fleet rollout, but accelerate remediation for exposed endpoints and high-risk user groups.
- Monitor vendor advisories and internal asset inventories to confirm all supported Apple OS versions are upgraded.
- Treat related image-handling crashes or instability as potentially security-relevant until patched systems are fully remediated.
Evidence notes
This debrief is based only on the supplied official corpus: the NVD record and Apple support references. The CVE was published on 2026-05-11 and last modified on 2026-05-13, and the supplied timeline fields use those dates. NVD lists the vulnerability status as Analyzed, the CVSS vector as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, and weakness CWE-119. No KEV entry or ransomware-campaign flag is present in the supplied enrichment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-28940 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-28940
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-28940 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28940
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/en-us/127110
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/en-us/127111
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/en-us/127115
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/en-us/127116
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/en-us/127118
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/en-us/127120
[email protected] - Release Notes, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.