CVE-2026-28963: Buffer Overflow
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intelligence to access sensitive user data during iPhone Mirroring.
Other sources
Accelerate. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
APFS. A buffer overflow was addressed with improved bounds checking.
— Apple
App Intents. A logic issue was addressed with improved restrictions.
— Apple
AppleJPEG. A memory corruption issue was addressed with improved input validation.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28991
- CVE-2026-28988
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-1837
- CVE-2026-28956
- CVE-2026-39869
- CVE-2026-28964
- CVE-2026-28936
- CVE-2026-28918
- CVE-2026-43659
- CVE-2026-43661
- CVE-2026-28977
- CVE-2026-28990
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-43655
- CVE-2026-43654
- CVE-2026-28897
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-43653
- CVE-2026-28985
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28940
- CVE-2026-28906
- CVE-2026-43656
- CVE-2026-28846
- CVE-2026-28963
- CVE-2026-28993
- CVE-2026-28974
- CVE-2026-28957
- CVE-2026-28996
- CVE-2026-43660
- CVE-2026-28907
- CVE-2026-28962
- CVE-2026-43658
- CVE-2026-28905
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28955
- CVE-2026-28903
- CVE-2026-28953
- CVE-2026-28902
- CVE-2026-28901
- CVE-2026-28913
- CVE-2026-28883
- CVE-2026-28958
- CVE-2026-28917
- CVE-2026-28947
- CVE-2026-28942
- CVE-2026-28971
- CVE-2026-28944
- CVE-2026-28994
- CVE-2026-28965
- CVE-2026-28920
Frequently Asked Questions
What is the severity of CVE-2026-28963?
CVE-2026-28963 is a privacy issue that allows an attacker with physical access to potentially access sensitive user data.
How do I fix CVE-2026-28963?
To fix CVE-2026-28963, update your device to iOS 26.5 or iPadOS 26.5.
What versions are affected by CVE-2026-28963?
CVE-2026-28963 affects versions of iOS and iPadOS prior to 26.5.
What types of devices are impacted by CVE-2026-28963?
CVE-2026-28963 impacts Apple iPhones and iPads running vulnerable OS versions.
Is there a workaround for CVE-2026-28963?
There are no documented workarounds for CVE-2026-28963; updating to the latest version is recommended.