A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.
History

Wed, 13 May 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 12 May 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Network Man‑In‑The‑Middle Attack Can Trigger Denial of Service via Null Pointer Dereference in Apple Operating Systems

Tue, 12 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Mon, 11 May 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos

Mon, 11 May 2026 22:45:00 +0000

Type Values Removed Values Added
Title Local Network Man‑In‑The‑Middle Attack Can Trigger Denial of Service via Null Pointer Dereference in Apple Operating Systems
Weaknesses CWE-476

Mon, 11 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-05-12T17:26:29.556Z

Reserved: 2026-03-03T16:36:03.994Z

Link: CVE-2026-28985

cve-icon Vulnrichment

Updated: 2026-05-12T17:26:25.790Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-11T21:18:58.520

Modified: 2026-05-13T14:08:02.203

Link: CVE-2026-28985

cve-icon Redhat

No data.