LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-28817

CVE-2026-28817 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 25, 2026

Apple macOS - Race Condition

Published: March 25, 2026Updated: March 25, 2026

Overview

Apple macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4 contain a race condition caused by improper state handling, letting sandboxed processes circumvent sandbox restrictions, exploit requires sandboxed process execution.

Severity & Score

Severity: High
CVSS Score: 8.1

Impact

Sandboxed processes can bypass restrictions, potentially leading to privilege escalation or unauthorized access.

Mitigation

Update to macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4 or later.

Details

CVE ID
CVE-2026-28817
Severity
High
CVSS Score
8.1
Type
race_condition
Status
unconfirmed

CWE

  • CWE-362

CVSS Metrics

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H