CVE-2026-28931

Summary

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.

Affected Software

VendorProductVersion RangeStatus
AppleiOS and iPadOS0 < 26.6affected
ApplemacOS0 < 26.6affected
AppletvOS0 < 26.6affected
ApplewatchOS0 < 26.6affected

Weaknesses

  • Connecting to a malicious NFS server may lead to kernel memory corruption

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References