CVE-2026-28817 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: March 25, 2026
Apple macOS - Race Condition
Published: March 25, 2026Updated: March 25, 2026
Overview
Apple macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4 contain a race condition caused by improper state handling, letting sandboxed processes circumvent sandbox restrictions, exploit requires sandboxed process execution.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Sandboxed processes can bypass restrictions, potentially leading to privilege escalation or unauthorized access.
Mitigation
Update to macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-28817
- Severity
- High
- CVSS Score
- 8.1
- Type
- race_condition
- Status
- unconfirmed
CWE
- CWE-362
CVSS Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H