
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28865 is an authentication bypass vulnerability in Apple's 802.1X network authentication implementation, affecting the state management logic across multiple Apple operating systems. Discovered by Héloïse Gollier and Mathy Vanhoef of KU Leuven, it was disclosed and patched on March 24, 2026. Affected platforms include iOS/iPadOS (before 18.7.7 and before 26.4), macOS Sonoma (before 14.8.5), macOS Sequoia (before 15.7.5), macOS Tahoe (before 26.4), tvOS (before 26.4), visionOS (before 26.4), and watchOS (before 26.4). The vulnerability carries a CVSS v3.1 base score of 7.5 (High) per NVD, though Feedly's category estimate rates it as Medium (Apple iOS 26.4 Advisory, Apple iOS 18.7.7 Advisory, Apple macOS Tahoe Advisory).
The vulnerability is rooted in improper authorization (CWE-285) within Apple's 802.1X supplicant implementation, where flawed authentication state management allows the authentication process to be bypassed or manipulated. 802.1X is a network access control protocol widely used in enterprise Wi-Fi and wired networks; a flaw in its state machine can allow an attacker to intercept or inject into network sessions before proper authentication is completed. Exploitation requires the attacker to be in a privileged network position (e.g., on the same network segment or performing a man-in-the-middle attack), meaning it is not remotely exploitable from an arbitrary internet location. No public technical write-up or proof-of-concept code has been identified at this time (Apple iOS 26.4 Advisory, Apple macOS Sequoia Advisory).
An attacker positioned on the same network segment or capable of performing a man-in-the-middle attack can intercept network traffic from affected Apple devices by exploiting the improper 802.1X authentication state handling. This primarily affects confidentiality, as intercepted traffic may expose sensitive data such as credentials, session tokens, or private communications transmitted over the network. The vulnerability does not directly enable code execution or persistent system compromise, but intercepted credentials could facilitate lateral movement within enterprise environments (Apple iOS 18.7.7 Advisory, Apple macOS Sonoma Advisory).
Apple has released patches across all affected platforms. Users should update to the following versions or later: iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, iPadOS 26.4, macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4. No configuration-based workaround has been published; upgrading to a patched version is the only recommended remediation. Organizations should prioritize patching devices connected to untrusted or shared networks where an attacker could more easily achieve a privileged network position (Apple iOS 26.4 Advisory, Apple macOS Tahoe Advisory, Apple macOS Sequoia Advisory).
The vulnerability was credited to Héloïse Gollier and Mathy Vanhoef of KU Leuven, researchers well known for their work on Wi-Fi and network protocol security (including the KRACK and DRAGONBLOOD attacks). Media coverage noted that iOS 18.7.7 was expanded to additional devices on April 1, 2026, specifically to deliver protections against the separately tracked "DarkSword" exploit, with CVE-2026-28865 included in that update. Security news outlets including GBHackers, CyberSecurityNews, and CyberInsider covered the iOS 18.7.7 rollout in the context of DarkSword protections, though CVE-2026-28865 itself received limited standalone attention given the absence of active exploitation (Apple iOS 18.7.7 Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."