Improper access control in macOS - CVE-2026-28867
Published: March 25, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code in kernel space.
The vulnerability exists due to improper access control in the kernel when handling local application requests. A local user can exploit this to execute arbitrary code in kernel space.
Successful exploitation may allow the attacker to gain full control over the system.
Affected software
iPadOS
Apple iOS
tvOS
visionOS
watchOS
How to mitigate CVE-2026-28867
iPadOS - addressed in versions 18.7.7 22H333, 26.4 23E246
Apple iOS - addressed in versions 18.7.7 22H333, 26.4 23E246
tvOS - update to 26.4 23L243
visionOS - update to 26.4
watchOS - update to 26.4 23T240
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple macOS Tahoe
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple iOS 18 and iPadOS 18
- Multiple vulnerabilities in Apple iOS 26 and iPadOS 26
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple visionOS