Description
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.
Published: 2026-05-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from inadequate authorization checks that let an application perform restricted actions, potentially exhausting system resources and making services unavailable. This results in a denial-of-service condition that a malicious or compromised app can trigger by executing in a normal user context. The weakness is characterized by improper authorization (CWE-284).

Affected Systems

Apple’s iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected when running versions prior to the releases that contain the fix. The fix is included in iOS 26.5, iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5. Devices running earlier versions remain vulnerable.

Risk and Exploitability

With a CVSS score of 7.5, the flaw is judged medium‑to‑high severity. The EPSS score of less than 1 % indicates a low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Attackers would most likely deploy a compromised application that runs locally on the device; no remote network interaction is required to trigger the denial‑of‑service.

Generated by OpenCVE AI on May 12, 2026 at 17:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the operating system to a patched version (iOS 26.5, iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, or watchOS 26.5).
  • Enforce strict app installation controls, ensuring that only apps signed by trusted developers and distributed through the App Store are allowed to execute.
  • Continuously monitor system logs for repeated crashes or service restarts, and investigate any abnormal behavior associated with application activity.

Generated by OpenCVE AI on May 12, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 12 May 2026 16:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Unauthorized Actions in Apple Operating Systems
Weaknesses CWE-399
CWE-640

Tue, 12 May 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 May 2026 22:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Unauthorized Actions in Apple Operating Systems
Weaknesses CWE-399
CWE-640

Mon, 11 May 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 11 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-05-12T13:21:46.371Z

Reserved: 2026-03-03T16:36:03.992Z

Link: CVE-2026-28974

cve-icon Vulnrichment

Updated: 2026-05-12T13:21:32.821Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-11T21:18:58.017

Modified: 2026-05-12T18:46:27.880

Link: CVE-2026-28974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T18:00:12Z

Weaknesses