CVE-2026-28964

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to access sensitive user data.
References
Link Resource
https://support.apple.com/en-us/127110 Release Notes Vendor Advisory
https://support.apple.com/en-us/127120 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-11 21:18

Updated : 2026-06-17 10:29


NVD link : CVE-2026-28964

Mitre link : CVE-2026-28964

CVE.ORG link : CVE-2026-28964


JSON object : View

Products Affected

apple

  • iphone_os
  • visionos
  • ipados
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information