Description
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.
Published: 2026-05-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw that can trigger an unexpected system termination when a malicious app exploits improper memory management. Based on the description, it is inferred that the attack vector is a malicious application executing on the target system. An attacker may cause a crash that disrupts availability without providing direct data or code‑execution capabilities.

Affected Systems

Apple iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5 are affected.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5 and an EPSS score of < 1%, indicating a very low probability of exploitation. Based on the description, the attack vector is a malicious application that can execute on the target system. A successful exploitation would lead to a denial‑of‑service condition by terminating system services or the entire OS. Although it is not listed in CISA's KEV catalog, the combined CVSS and low EPSS suggest a low exploitation probability.

Generated by OpenCVE AI on May 12, 2026 at 16:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest patched versions: iOS 18.7.9+, iPadOS 18.7.9+, macOS Sequoia 15.7.7+, macOS Sonoma 14.8.7+, macOS Tahoe 26.5+, tvOS 26.5+, visionOS 26.5+, watchOS 26.5+
  • If an update is not immediately available, avoid running applications from untrusted sources until a patch is applied
  • Monitor Apple support and update channels for future advisories that might address related memory‑management issues

Generated by OpenCVE AI on May 12, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 12 May 2026 17:00:00 +0000

Type Values Removed Values Added
Title Use After Free Leading to Unexpected System Termination in Apple Operating Systems

Tue, 12 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 May 2026 23:00:00 +0000

Type Values Removed Values Added
Title Use After Free Leading to Unexpected System Termination in Apple Operating Systems
Weaknesses CWE-416

Mon, 11 May 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 11 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-05-12T13:23:22.141Z

Reserved: 2026-03-03T16:36:03.992Z

Link: CVE-2026-28969

cve-icon Vulnrichment

Updated: 2026-05-12T13:23:13.314Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-11T21:18:57.700

Modified: 2026-05-12T17:15:25.340

Link: CVE-2026-28969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T16:45:16Z

Weaknesses