CVE-2026-28847: Apple Safari Regular Expression Duplicate Named Groups Heap-based Buffer Overflow Remote Code Execution Vulnerability
Accelerate. An out-of-bounds read was addressed with improved bounds checking.
Other sources
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
Accounts. An authorization issue was addressed with improved state management.
— Apple
APFS. A buffer overflow was addressed with improved bounds checking.
— Apple
App Intents. A logic issue was addressed with improved restrictions.
— Apple
AppleJPEG. A memory corruption issue was addressed with improved input validation.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.7.9 - Upgrade
Upgrade
Apple Safarito a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.7.9 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.7.9 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 26.5 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 26.5 - Compensating control
Ensure user interaction is required: only users should interact by visiting malicious pages or opening malicious files, and use user-consent prompts (additional prompt for user consent) to reduce exposure to unauthorized actions while awaiting patching.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28991
- CVE-2026-28988
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-1837
- CVE-2026-28956
- CVE-2026-39869
- CVE-2026-28922
- CVE-2026-28936
- CVE-2026-28918
- CVE-2026-28915
- CVE-2026-43659
- CVE-2026-28923
- CVE-2026-28925
- CVE-2026-43661
- CVE-2026-28977
- CVE-2026-28990
- CVE-2026-28978
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-43655
- CVE-2026-43654
- CVE-2026-28908
- CVE-2026-28954
- CVE-2026-28897
- CVE-2026-28952
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-28929
- CVE-2026-43653
- CVE-2026-28985
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28941
- CVE-2026-28940
- CVE-2026-28961
- CVE-2026-28906
- CVE-2026-43656
- CVE-2026-43652
- CVE-2026-39870
- CVE-2026-28846
- CVE-2026-28993
- CVE-2026-28848
- CVE-2026-28930
- CVE-2026-28974
- CVE-2026-28996
- CVE-2026-28919
- CVE-2026-28924
- CVE-2026-39871
- CVE-2026-28976
- CVE-2026-43660
- CVE-2026-28907
- CVE-2026-28962
- CVE-2026-43658
- CVE-2026-28905
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28955
- CVE-2026-28903
- CVE-2026-28953
- CVE-2026-28902
- CVE-2026-28901
- CVE-2026-28913
- CVE-2026-28883
- CVE-2026-28958
- CVE-2026-28917
- CVE-2026-28947
- CVE-2026-28946
- CVE-2026-28942
- CVE-2026-28971
- CVE-2026-28944
- CVE-2026-28819
- CVE-2026-28994
- CVE-2026-28914
- CVE-2026-28920
- CVE-2026-28964
- CVE-2026-28963
- CVE-2026-28957
- CVE-2026-28965
- CVE-2026-28877
- CVE-2026-28872
- CVE-2026-28894
- CVE-2026-28870
- CVE-2026-28882
- CVE-2026-28873
Frequently Asked Questions
What is the severity of CVE-2026-28847?
CVE-2026-28847 is classified as a moderate severity vulnerability that affects multiple Apple operating systems.
How do I fix CVE-2026-28847?
To fix CVE-2026-28847, upgrade your affected Apple operating system to the latest version specified by the vendor.
What systems are affected by CVE-2026-28847?
CVE-2026-28847 affects macOS Tahoe, iOS, iPadOS, visionOS, tvOS, watchOS, and Safari versions up to 26.5.
What type of vulnerability is CVE-2026-28847?
CVE-2026-28847 includes an out-of-bounds read, buffer overflow, and issues with permissions and authorization.
Are there workarounds for CVE-2026-28847?
There are no official workarounds for CVE-2026-28847; applying the latest updates is the recommended course of action.