
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28852 is a stack overflow vulnerability in Apple's UIFoundation framework that allows a malicious app to cause a denial-of-service condition. Discovered and reported by Caspian Tarafdar, it was disclosed and patched on March 24, 2026. The vulnerability affects iOS and iPadOS (before 18.7.7 and before 26.4), macOS Sequoia (before 15.7.5), macOS Tahoe (before 26.4), tvOS (before 26.4), visionOS (before 26.4), and watchOS (before 26.4). It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory iOS 26.4, Apple Advisory iOS 18.7.7).
The vulnerability is rooted in improper input validation (CWE-20) within Apple's UIFoundation framework, which leads to a stack overflow when processing specially crafted input. The attack vector is local, requiring user interaction — specifically, a user must run or interact with a malicious application on the affected device. No authentication or elevated privileges are required for the app to trigger the overflow. The fix was implemented by improving input validation within the UIFoundation component across all affected platforms (Apple Advisory iOS 26.4, Apple Advisory macOS Sequoia 15.7.5).
Successful exploitation results in a denial-of-service condition, causing the affected application or device to become unresponsive or crash. The impact is limited to availability — there is no confidentiality or integrity impact associated with this vulnerability. Because the attack requires local access and user interaction with a malicious app, the scope of impact is confined to the targeted device and does not facilitate lateral movement or data exfiltration (Apple Advisory tvOS 26.4, Apple Advisory macOS Tahoe 26.4).
Apple has released patches across all affected platforms. Users should update to the following versions or later: iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4. No configuration-based workarounds have been published; updating to a patched version is the only recommended remediation. Users should also avoid installing or interacting with untrusted applications as a general precaution (Apple Advisory iOS 26.4, Apple Advisory macOS Sequoia 15.7.5).
The vulnerability was part of a broader March 2026 Apple security update that addressed over 140 vulnerabilities across Apple's product ecosystem, which received coverage from security news outlets and aggregators. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-28852 has been identified, consistent with its medium severity and denial-of-service-only impact. The broader update batch was noted by CIS and security digest services as a significant patch cycle (Apple Advisory iOS 26.4).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."