216.73.216.6

CVE-2026-28906

· Published 11/05/2026 21:18 · Modified 12/05/2026 18:16

Labels: CVE-2026-28906 2026-05-11CVE-2026-28906CWE-359[email protected]

Essential information

Published
11/05/2026 21:18
Modified
12/05/2026 18:16
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
apple / ios cpe:2.3:a:apple:ios:18.7.9:*:*:*:*:*:*:*
apple / ipados cpe:2.3:a:apple:ipados:18.7.9:*:*:*:*:*:*:*
apple / ios cpe:2.3:a:apple:ios:26.5:*:*:*:*:*:*:*
apple / ipados cpe:2.3:a:apple:ipados:26.5:*:*:*:*:*:*:*
apple / macos sequoia cpe:2.3:a:apple:macos_sequoia:15.7.7:*:*:*:*:*:*:*
apple / macos sonoma cpe:2.3:a:apple:macos_sonoma:14.8.7:*:*:*:*:*:*:*
apple / macos tahoe cpe:2.3:a:apple:macos_tahoe:26.5:*:*:*:*:*:*:*
apple / visionos cpe:2.3:a:apple:visionos:26.5:*:*:*:*:*:*:*

References