CVE-2026-28872 PUBLISHED

Assigner: apple
Reserved: 03.03.2026 Published: 11.05.2026 Updated: 11.05.2026

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.

Product Status

Vendor Apple
Product iOS and iPadOS
Versions
  • affected from 0 to 18.7.9 (excl.)
  • affected from 0 to 26.4 (excl.)

References

Problem Types

  • A remote attacker may be able to cause a denial-of-service