vulnerability
OS X update for Wi-Fi (CVE-2026-28994)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:A/AC:M/Au:N/C:N/I:N/A:C) | May 12, 2026 | May 12, 2026 | May 13, 2026 |
Severity
6
CVSS
(AV:A/AC:M/Au:N/C:N/I:N/A:C)
Published
May 12, 2026
Added
May 12, 2026
Modified
May 13, 2026
Description
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Wi-Fi packets.
Solutions
apple-osx-upgrade-14_8_7apple-osx-upgrade-15_7_7apple-osx-upgrade-26_5
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.