CVE-2026-28991
high
CVSS v3
7.5
CVSS v4 NEW
โ
VIR risk
7.5
Description
visionOS 26.5
Predictions
Exploit likelihood
83%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Source: Apple Security HT ยท View original โ ยท proprietary-no-redistribution
Full prose not cached โ VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.
Affected
| Vendor | Product | Version |
|---|---|---|
| apple | Accelerate | macOS Tahoe |
| apple | Accounts | macOS Tahoe |
| apple | APFS | macOS Tahoe |
| apple | App Intents | macOS Tahoe |
| apple | AppleJPEG | macOS Tahoe |
| apple | AppleJPEG | macOS Tahoe |
| apple | Audio | macOS Tahoe |
| apple | CoreMedia | macOS Tahoe |
| apple | CoreServices | macOS Tahoe |
| apple | CoreSymbolication | macOS Tahoe |
| apple | CUPS | macOS Tahoe |
| apple | FileProvider | macOS Tahoe |
| apple | GPU Drivers | macOS Tahoe |
| apple | HFS | macOS Tahoe |
| apple | ImageIO | macOS Tahoe |
| apple | ImageIO | macOS Tahoe |
| apple | ImageIO | macOS Tahoe |
| apple | Installer | macOS Tahoe |
| apple | IOHIDFamily | macOS Tahoe |
| apple | IOHIDFamily | macOS Tahoe |
| apple | IOKit | macOS Tahoe |
| apple | IOSurfaceAccelerator | macOS Tahoe |
| apple | Kernel | macOS Tahoe |
| apple | Kernel | macOS Tahoe |
| apple | Kernel | macOS Tahoe |
| apple | Kernel | macOS Tahoe |
| apple | Kernel | macOS Tahoe |
| apple | Kernel | macOS Tahoe |
| apple | Kernel | macOS Tahoe |
| apple | Kernel | macOS Tahoe |
OS impact
macOS Mixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 26.5 | Fixed | โ |
| โ | Affected | 26.5 |
apple Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 26.5 | Fixed | โ |
ios Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 26.5 | Fixed | โ |
tvos Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 26.5 | Fixed | โ |
watchos Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 26.5 | Fixed | โ |
References
CWEs
CWE-125
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.