CVE-2026-28895: Medium severity Apple iOS vulnerability
802.1X. An authentication issue was addressed with improved state management.
Other sources
Accounts. An authorization issue was addressed with improved state management.
— Apple
App Protection. The issue was addressed with improved checks.
— Apple
The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28865
- CVE-2026-28877
- CVE-2026-28895
- CVE-2026-28879
- CVE-2026-28822
- CVE-2026-28874
- CVE-2026-28875
- CVE-2026-28872
- CVE-2026-28894
- CVE-2026-28866
- CVE-2026-20690
- CVE-2026-28886
- CVE-2026-28878
- CVE-2025-14524
- CVE-2026-28876
- CVE-2026-28870
- CVE-2026-28880
- CVE-2026-28833
- CVE-2025-64505
- CVE-2026-28868
- CVE-2026-28867
- CVE-2026-20698
- CVE-2026-20687
- CVE-2026-28882
- CVE-2026-20692
- CVE-2026-20688
- CVE-2026-28873
- CVE-2026-28863
- CVE-2026-28864
- CVE-2026-28860
- CVE-2026-28856
- CVE-2026-28858
- CVE-2026-28967
- CVE-2026-28852
- CVE-2026-20657
- CVE-2026-20665
- CVE-2026-20643
- CVE-2026-28871
- CVE-2026-20664
- CVE-2026-28857
- CVE-2026-28861
- CVE-2026-28859
- CVE-2026-20691
Frequently Asked Questions
What is the severity of CVE-2026-28895?
CVE-2026-28895 has been classified as a high-severity authentication and authorization issue in Apple's iOS and iPadOS.
How do I fix CVE-2026-28895?
To mitigate CVE-2026-28895, update your device to iOS or iPadOS version 26.4 or later.
What types of devices are affected by CVE-2026-28895?
CVE-2026-28895 affects Apple iOS and iPadOS devices prior to version 26.4.
What specific vulnerabilities does CVE-2026-28895 address?
CVE-2026-28895 addresses authentication and authorization issues with improved state management in the affected software.
Is there a workaround for CVE-2026-28895?
There is no known workaround for CVE-2026-28895, and users should update their devices to the latest version to ensure security.