Home

Description

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination.

PUBLISHED Reserved 2026-03-03 | Published 2026-05-11 | Updated 2026-05-11 | Assigner apple

Problem types

Parsing a maliciously crafted file may lead to an unexpected app termination

Product status

Any version before 26.5
affected

Any version before 26.5
affected

Any version before 26.5
affected

Any version before 26.5
affected

Any version before 26.5
affected

References

support.apple.com/en-us/127110

support.apple.com/en-us/127115

support.apple.com/en-us/127118

support.apple.com/en-us/127119

support.apple.com/en-us/127120

cve.org (CVE-2026-28918)

nvd.nist.gov (CVE-2026-28918)

Download JSON