CVE-2026-28855: Use After Free
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3. An app may be able to access protected user data.
Other sources
Accessibility. A privacy issue was addressed by removing sensitive data.
— Apple
Accessibility. An inconsistent user interface issue was addressed with improved state management.
— Apple
Admin Framework. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
AppleEvents. An authorization issue was addressed with improved state management.
— Apple
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20645
- CVE-2026-20674
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20638
- CVE-2026-20660
- CVE-2026-20686
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20617
- CVE-2026-20615
- CVE-2026-20627
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20649
- CVE-2026-20675
- CVE-2026-20634
- CVE-2026-20654
- CVE-2026-20626
- CVE-2026-20671
- CVE-2026-20663
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20655
- CVE-2026-20677
- CVE-2026-20694
- CVE-2026-20642
- CVE-2026-20628
- CVE-2026-20678
- CVE-2026-28855
- CVE-2026-20682
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20640
- CVE-2026-20661
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
- CVE-2026-20621
- CVE-2026-20669
- CVE-2026-20670
- CVE-2026-20625
- CVE-2026-20624
- CVE-2026-20639
- CVE-2026-20681
- CVE-2026-20629
- CVE-2026-20601
- CVE-2026-20623
- CVE-2026-20620
- CVE-2026-20630
- CVE-2026-20673
- CVE-2026-20651
- CVE-2026-20616
- CVE-2026-20603
- CVE-2026-20666
- CVE-2026-20614
- CVE-2026-20656
- CVE-2026-20658
- CVE-2026-20610
- CVE-2026-20622
- CVE-2026-20648
- CVE-2026-20662
- CVE-2026-20647
- CVE-2026-20612
- CVE-2026-20699
- CVE-2026-20619
- CVE-2026-20618
- CVE-2026-20605
- CVE-2026-20646
- CVE-2026-20602
Frequently Asked Questions
What is the severity of CVE-2026-28855?
CVE-2026-28855 is considered a high severity vulnerability due to its ability to allow unauthorized access to protected user data.
How do I fix CVE-2026-28855?
To fix CVE-2026-28855, update your devices to iOS 26.3, iPadOS 26.3, or macOS Tahoe 26.3.
Which software is affected by CVE-2026-28855?
CVE-2026-28855 affects Apple iOS versions prior to 26.3, Apple iPadOS versions prior to 26.3, and macOS Tahoe versions prior to 26.3.
What type of issue is CVE-2026-28855?
CVE-2026-28855 is classified as a permissions issue that allows potential unauthorized access to protected user data.
Can CVE-2026-28855 affect my personal data?
Yes, CVE-2026-28855 poses a risk to personal data stored on affected devices if not patched.