CVE-2026-28872: Input Validation
802.1X. An authentication issue was addressed with improved state management.
Other sources
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.
— MITRE
Accounts. An authorization issue was addressed with improved state management.
— Apple
APFS. A buffer overflow was addressed with improved bounds checking.
— Apple
App Intents. A logic issue was addressed with improved restrictions.
— Apple
App Protection. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28877
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-39869
- CVE-2026-28872
- CVE-2026-28894
- CVE-2026-28936
- CVE-2026-43659
- CVE-2026-28870
- CVE-2026-28977
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-43654
- CVE-2026-28954
- CVE-2026-28897
- CVE-2026-28952
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-28882
- CVE-2026-28929
- CVE-2026-43653
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28940
- CVE-2026-28941
- CVE-2026-28906
- CVE-2026-28873
- CVE-2026-43656
- CVE-2026-28846
- CVE-2026-28993
- CVE-2026-28957
- CVE-2026-28907
- CVE-2026-43660
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28903
- CVE-2026-28955
- CVE-2026-28953
- CVE-2026-28962
- CVE-2026-28917
- CVE-2026-28819
- CVE-2026-28994
- CVE-2026-28920
- CVE-2026-28865
- CVE-2026-28895
- CVE-2026-28879
- CVE-2026-28822
- CVE-2026-28874
- CVE-2026-28875
- CVE-2026-28866
- CVE-2026-20690
- CVE-2026-28886
- CVE-2026-28878
- CVE-2025-14524
- CVE-2026-28876
- CVE-2026-28880
- CVE-2026-28833
- CVE-2025-64505
- CVE-2026-28868
- CVE-2026-28867
- CVE-2026-20698
- CVE-2026-20687
- CVE-2026-20692
- CVE-2026-20688
- CVE-2026-28863
- CVE-2026-28864
- CVE-2026-28860
- CVE-2026-28856
- CVE-2026-28858
- CVE-2026-28967
- CVE-2026-28852
- CVE-2026-20657
- CVE-2026-20665
- CVE-2026-20643
- CVE-2026-28871
- CVE-2026-20664
- CVE-2026-28857
- CVE-2026-28861
- CVE-2026-28859
- CVE-2026-20691
Frequently Asked Questions
What is the severity of CVE-2026-28872?
CVE-2026-28872 has a moderate severity level primarily due to the potential for denial-of-service attacks.
How do I fix CVE-2026-28872?
To fix CVE-2026-28872, update your device to iOS 18.7.9, iPadOS 18.7.9, iOS 26.4, or iPadOS 26.4.
What type of issue is described in CVE-2026-28872?
CVE-2026-28872 describes an authentication issue related to state management and a resource exhaustion issue due to inadequate input validation.
Who is affected by CVE-2026-28872?
CVE-2026-28872 affects users of affected versions of Apple iOS and iPadOS prior to the specified remediation versions.
Can CVE-2026-28872 be exploited remotely?
Yes, a remote attacker may exploit CVE-2026-28872 to cause a denial-of-service on affected devices.