CVE-2026-28872
Received Received - Intake
Resource Exhaustion in iOS and iPadOS

Publication date: 2026-05-11

Last updated on: 2026-05-11

Assigner: Apple Inc.

Description
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-11
Last Modified
2026-05-11
Generated
2026-05-12
AI Q&A
2026-05-12
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
apple ios to 18.7.9 (inc)
apple ipad_os to 18.7.9 (inc)
apple ios to 26.4 (inc)
apple ipad_os to 26.4 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a resource exhaustion issue caused by insufficient input validation. It allows a remote attacker to potentially cause a denial-of-service condition on affected Apple iOS and iPadOS devices.


How can this vulnerability impact me? :

The impact of this vulnerability is that a remote attacker may be able to cause a denial-of-service, which could make the affected device unresponsive or unavailable to the user.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update your devices to the fixed versions of the operating systems: iOS 18.7.9, iPadOS 18.7.9, iOS 26.4, or iPadOS 26.4.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart