Information disclosure in macOS - CVE-2026-28870
Published: March 25, 2026
Vulnerability identifier: #VU124387
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28870
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access controls in GeoServices when handling local application requests. A local user can exploit this to disclose sensitive information.
Access to the local system is required to exploit this vulnerability.
Affected software
macOS
iPadOS
Apple iOS
tvOS
visionOS
watchOS
iPadOS
Apple iOS
tvOS
visionOS
watchOS
How to mitigate CVE-2026-28870
Install update from vendor's website.
macOS - update to 26.4 25E246
iPadOS - addressed in versions 18.7.9 22H355, 26.4 23E246
Apple iOS - addressed in versions 18.7.9 22H355, 26.4 23E246
tvOS - update to 26.4 23L243
visionOS - update to 26.4
watchOS - update to 26.4 23T240
iPadOS - addressed in versions 18.7.9 22H355, 26.4 23E246
Apple iOS - addressed in versions 18.7.9 22H355, 26.4 23E246
tvOS - update to 26.4 23L243
visionOS - update to 26.4
watchOS - update to 26.4 23T240