CVE Tools
Back to feed
Patch released iOS mobile macOS Apple rce

Apple Patches iOS and macOS - SANS Internet Storm Center

SANS Internet Storm Center·By SANS Internet Storm Center··9 min read
CVE Tools coverage

Apple has issued security updates for iOS and macOS to remediate a broad set of vulnerabilities affecting multiple system components. The release addresses numerous flaws, including kernel memory corruption that could allow privilege escalation, WebKit bugs enabling data exfiltration or crashes, and ImageIO defects leading to arbitrary code execution.

Key risks include potential remote exploitation through crafted web content or media files, as well as local sandbox escape vectors in frameworks like libc and MediaRemote. Users are advised to install the latest operating system updates to mitigate these threats.

CVE-2026-28958: An app may be able to access sensitive user data.
Affects WebKit   x   CVE-2026-28973: A malicious app may be able to break out of its sandbox.
Affects libc   x   CVE-2026-28984: Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affe…

Continue reading on SANS Internet Storm Center