CVE-2026-28877: Infoleak
802.1X. An authentication issue was addressed with improved state management.
Other sources
Accounts. An authorization issue was addressed with improved state management.
— Apple
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.
— NVD
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28877
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-39869
- CVE-2026-28872
- CVE-2026-28894
- CVE-2026-28936
- CVE-2026-43659
- CVE-2026-28870
- CVE-2026-28977
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-43654
- CVE-2026-28954
- CVE-2026-28897
- CVE-2026-28952
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-28882
- CVE-2026-28929
- CVE-2026-43653
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28940
- CVE-2026-28941
- CVE-2026-28906
- CVE-2026-28873
- CVE-2026-43656
- CVE-2026-28846
- CVE-2026-28993
- CVE-2026-28957
- CVE-2026-28907
- CVE-2026-43660
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28903
- CVE-2026-28955
- CVE-2026-28953
- CVE-2026-28962
- CVE-2026-28917
- CVE-2026-28819
- CVE-2026-28994
- CVE-2026-28920
- CVE-2026-28865
- CVE-2026-28895
- CVE-2026-28879
- CVE-2026-28822
- CVE-2026-28874
- CVE-2026-28875
- CVE-2026-28866
- CVE-2026-20690
- CVE-2026-28886
- CVE-2026-28878
- CVE-2025-14524
- CVE-2026-28876
- CVE-2026-28880
- CVE-2026-28833
- CVE-2025-64505
- CVE-2026-28868
- CVE-2026-28867
- CVE-2026-20698
- CVE-2026-20687
- CVE-2026-20692
- CVE-2026-20688
- CVE-2026-28863
- CVE-2026-28864
- CVE-2026-28860
- CVE-2026-28856
- CVE-2026-28858
- CVE-2026-28967
- CVE-2026-28852
- CVE-2026-20657
- CVE-2026-20665
- CVE-2026-20643
- CVE-2026-28871
- CVE-2026-20664
- CVE-2026-28857
- CVE-2026-28861
- CVE-2026-28859
- CVE-2026-20691
- CVE-2025-55753
- CVE-2025-58098
- CVE-2025-59775
- CVE-2025-65082
- CVE-2025-66200
- CVE-2026-20637
- CVE-2026-28824
- CVE-2026-20699
- CVE-2026-20660
- CVE-2026-20639
- CVE-2026-28821
- CVE-2026-28838
- CVE-2026-28888
- CVE-2026-20633
- CVE-2026-28892
- CVE-2026-28832
- CVE-2026-20668
- CVE-2026-28834
- CVE-2026-20695
- CVE-2026-28829
- CVE-2026-20607
- CVE-2026-20651
- CVE-2026-20694
- CVE-2026-28891
- CVE-2026-20701
- CVE-2026-28839
- CVE-2026-28827
- CVE-2026-28816
- CVE-2026-28826
- CVE-2026-20693
- CVE-2026-28862
- CVE-2026-28831
- CVE-2026-28817
- CVE-2026-28835
- CVE-2026-28825
- CVE-2026-28818
- CVE-2026-20697
- CVE-2026-28828
- CVE-2026-28823
- CVE-2026-20696
- CVE-2026-20684
- CVE-2026-28910
- CVE-2026-28893
- CVE-2026-28881
- CVE-2026-28842
- CVE-2026-28841
- CVE-2026-28845
- CVE-2026-20632
- CVE-2026-20631
- CVE-2026-28840
- CVE-2026-28830
- CVE-2026-28820
- CVE-2026-28837
- CVE-2026-28844
Frequently Asked Questions
What is the severity of CVE-2026-28877?
CVE-2026-28877 has been classified as a critical vulnerability due to its impact on authentication and authorization.
How do I fix CVE-2026-28877?
To mitigate CVE-2026-28877, update your devices to iOS 26.4, iPadOS 26.4, macOS Sequoia 15.7.5, or other affected platforms as specified.
What devices are affected by CVE-2026-28877?
CVE-2026-28877 affects devices running iOS, iPadOS, macOS Tahoe, watchOS, and visionOS prior to the specified versions.
What types of issues does CVE-2026-28877 address?
CVE-2026-28877 addresses authentication and authorization issues stemming from insufficient state management.
Is there a workaround for CVE-2026-28877 before applying the update?
Currently, there are no recommended workarounds for CVE-2026-28877, and users are advised to apply the available updates promptly.