CVE-2026-28967: Buffer Overflow
802.1X. An authentication issue was addressed with improved state management.
Other sources
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4. An attacker in a privileged network position may be able to cause a denial-of-service.
— MITRE
Accounts. An authorization issue was addressed with improved state management.
— Apple
App Protection. The issue was addressed with improved checks.
— Apple
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
Audio. A type confusion issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28865
- CVE-2026-28877
- CVE-2026-28895
- CVE-2026-28879
- CVE-2026-28822
- CVE-2026-28874
- CVE-2026-28875
- CVE-2026-28872
- CVE-2026-28894
- CVE-2026-28866
- CVE-2026-20690
- CVE-2026-28886
- CVE-2026-28878
- CVE-2025-14524
- CVE-2026-28876
- CVE-2026-28870
- CVE-2026-28880
- CVE-2026-28833
- CVE-2025-64505
- CVE-2026-28868
- CVE-2026-28867
- CVE-2026-20698
- CVE-2026-20687
- CVE-2026-28882
- CVE-2026-20692
- CVE-2026-20688
- CVE-2026-28873
- CVE-2026-28863
- CVE-2026-28864
- CVE-2026-28860
- CVE-2026-28856
- CVE-2026-28858
- CVE-2026-28967
- CVE-2026-28852
- CVE-2026-20657
- CVE-2026-20665
- CVE-2026-20643
- CVE-2026-28871
- CVE-2026-20664
- CVE-2026-28857
- CVE-2026-28861
- CVE-2026-28859
- CVE-2026-20691
- CVE-2026-20637
- CVE-2026-20668
- CVE-2025-43534
- CVE-2025-43376
Frequently Asked Questions
What is the severity of CVE-2026-28967?
CVE-2026-28967 has been rated as a denial-of-service vulnerability.
How do I fix CVE-2026-28967?
To fix CVE-2026-28967, update your device to iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, or iPadOS 26.4.
What devices are affected by CVE-2026-28967?
CVE-2026-28967 affects Apple iOS and iPadOS versions up to 18.7.7 and 26.4.
What type of attack can exploit CVE-2026-28967?
CVE-2026-28967 can be exploited by an attacker in a privileged network position to cause denial-of-service.
Is it safe to use devices with CVE-2026-28967 without the update?
Using devices with CVE-2026-28967 without the update poses a risk of denial-of-service.