
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28886 is a null pointer dereference vulnerability in Apple's CoreUtils component that allows a user in a privileged network position to cause a denial-of-service condition. Discovered and reported by Etienne Charron and Victoria Martini of Renault, it was disclosed and patched on March 24, 2026. The vulnerability affects iOS and iPadOS (before 18.7.7 and before 26.4), macOS Sequoia (before 15.7.5), macOS Sonoma (before 14.8.5), macOS Tahoe (before 26.4), tvOS (before 26.4), visionOS (before 26.4), and watchOS (before 26.4). It carries a CVSS v3.1 base score of 5.9 (Medium) (Apple Advisory iOS 26.4, Apple Advisory iOS 18.7.7, Apple Advisory macOS Tahoe).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and resides in Apple's CoreUtils component. An attacker positioned in a privileged network location (e.g., a man-in-the-middle position on the same network segment) can send specially crafted network input that triggers a null pointer dereference due to insufficient input validation, causing the affected process or system to crash. The attack requires no authentication and no user interaction, but does require the attacker to be in a privileged network position (high attack complexity), limiting opportunistic exploitation. Apple addressed the issue by implementing improved input validation (Apple Advisory iOS 26.4, Apple Advisory macOS Sequoia).
Successful exploitation results in a denial-of-service condition on the affected Apple device, causing service unavailability. The impact is limited to availability — there is no confidentiality or integrity impact, and no evidence of code execution potential. The broad scope of affected platforms (iPhone, iPad, Mac, Apple TV, Apple Watch, Apple Vision Pro) means a wide range of consumer and enterprise devices could be disrupted if an attacker achieves the required privileged network position (Apple Advisory macOS Tahoe, Apple Advisory macOS Sonoma).
Apple has released patches across all affected platforms. Users should update to the following versions or later: iOS 18.7.7, iOS 26.4, iPadOS 18.7.7, iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4. No configuration-based workaround is available; upgrading is the only remediation. As an interim measure, organizations should consider network segmentation to limit exposure of Apple devices to untrusted or potentially compromised network positions (Apple Advisory iOS 26.4, Apple Advisory macOS Tahoe, Apple Advisory macOS Sequoia).
The vulnerability was part of a broader March 2026 Apple security update that addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS, which received coverage from security news outlets and aggregators. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-28886 has been identified, consistent with its medium severity and DoS-only impact.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."