CVE-2026-28947
Ein Angreifer kann mehrere Schwachstellen in Apple Safari, Apple macOS, Apple iOS und Apple iPadOS ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, Speicherbeschädigungen zu verursachen oder einen Denial-of-Service-Zustand herbeizuführen.
CSIRTS triage
- What
- Multiple vulnerabilities across macOS, iOS, and iPadOS enable code execution, security bypass, information disclosure, data manipulation, memory corruption, and denial of service.
- Who is affected
- Apple macOS, iOS, and iPadOS devices running unpatched versions.
- Urgency
- High severity; affects multiple platforms with code execution and memory corruption potential; patch immediately.
- Action
- Update Apple macOS, iOS, and iPadOS to latest security releases addressing CVE-2026-28947, CVE-2026-28958, CVE-2026-28973, CVE-2026-28979, CVE-2026-28984, CVE-2026-28990, CVE-2026-28996, and CVE-2026-3783.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-28947
Get an email if CVE-2026-28947 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
Advisory coverage (8)
- high[UPDATE] [hoch] Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellencert-bund · 2026-09-15
- high[UPDATE] [hoch] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund · 2026-09-09
- high[UPDATE] [high] WebKitGTK: Multiple vulnerabilitiescert-bund · 2026-09-01
- unknownUSN-8703-1: WebKitGTK vulnerabilitiesubuntu · 2026-08-31
- unknownNCSC-2026-0319 [1.00] [M/H] Vulnerabilities resolved in Apple iOS and iPadOSncsc-nl · 2026-08-20
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-08-18
- unknownMultiple vulnerabilities in Apple products (August 18, 2026)cert-fr-avis · 2026-08-18
- unknownDSA-6398-1 webkit2gtk - security updatedebian · 2026-07-23
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-28947)