CVE-2026-28856 PUBLISHED

Assigner: apple
Reserved: 03.03.2026 Published: 25.03.2026 Updated: 25.03.2026

The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26.4, visionOS 26.4, watchOS 26.4. An attacker with physical access to a locked device may be able to view sensitive user information.

Product Status

Vendor Apple
Product iOS and iPadOS
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product visionOS
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product watchOS
Versions
  • affected from 0 to 26.4 (excl.)

References

Problem Types

  • An attacker with physical access to a locked device may be able to view sensitive user information