CVE-2026-28907
Ein Angreifer kann mehrere Schwachstellen in Apple iOS und Apple iPadOS ausnutzen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, und um Sicherheitsvorkehrungen zu umgehen.
CSIRTS triage
- What
- Multiple vulnerabilities in WebKitGTK can be exploited to conduct denial of service attacks, disclose information, and bypass security precautions.
- Who is affected
- Remote attackers can exploit these vulnerabilities in WebKitGTK deployments.
- Urgency
- Remediation is urgent due to the high severity and potential for exploitation.
- Action
- Update to the latest version of WebKitGTK to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-28907
Get an email if CVE-2026-28907 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Advisory coverage (4)
- high[UPDATE] [hoch] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund · 2026-09-09
- high[UPDATE] [high] WebKitGTK: Multiple vulnerabilitiescert-bund · 2026-09-01
- unknownUSN-8703-1: WebKitGTK vulnerabilitiesubuntu · 2026-08-31
- unknownDSA-6398-1 webkit2gtk - security updatedebian · 2026-07-23
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-28907)