Out-of-Bounds Read Vulnerability in Swift Crypto by Apple
CVE-2026-28815
7.5HIGH
What is CVE-2026-28815?
A vulnerability exists in Swift Crypto where a remote attacker can exploit a flaw in the C decapsulation method by sending a specially crafted X-Wing HPKE encapsulated key. This can lead to an out-of-bounds read, potentially causing application crashes or unintended memory disclosure, depending on the runtime safeguards in place. The issue has been addressed in version 4.3.1 of Swift Crypto, and users are advised to upgrade to ensure their systems remain secure.
Affected Version(s)
macOS 4.0.0 < 4.3.1