Improper access control in macOS - CVE-2026-28867

 

Improper access control in macOS - CVE-2026-28867

Published: March 25, 2026


Vulnerability identifier: #VU124390
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28867
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code in kernel space.

The vulnerability exists due to improper access control in the kernel when handling local application requests. A local user can exploit this to execute arbitrary code in kernel space.

Successful exploitation may allow the attacker to gain full control over the system.


Affected software

macOS
iPadOS
Apple iOS
tvOS
visionOS
watchOS

How to mitigate CVE-2026-28867

Install update from vendor's website.

macOS - addressed in versions 26.4 25E246, 15.7.5 24G624
iPadOS - addressed in versions 18.7.7 22H333, 26.4 23E246
Apple iOS - addressed in versions 18.7.7 22H333, 26.4 23E246
tvOS - update to 26.4 23L243
visionOS - update to 26.4
watchOS - update to 26.4 23T240

External References

Related Security Bulletins