Out-of-Bounds Write Vulnerability in macOS by Apple
CVE-2026-28825

5.5MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
25 March 2026

What is CVE-2026-28825?

An out-of-bounds write vulnerability allows apps to access and modify protected areas of the file system. This security flaw was mitigated through enhanced bounds checking in the latest macOS updates. Users are encouraged to update their systems to ensure protection against potential exploitations that could compromise sensitive system files.

Affected Version(s)

macOS 0 < 14.8.5

macOS 0 < 15.7.5

macOS 0 < 26.4

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.