File Quarantine Bypass in macOS by Apple
CVE-2026-28900

Currently unrated

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-28900?

A file quarantine bypass vulnerability has been discovered in macOS, allowing maliciously crafted ZIP archives to evade Gatekeeper checks intended to protect users. This can enable untrusted applications to execute without proper scrutiny, posing significant security risks. Apple has addressed this issue in the recent updates for macOS Sequoia and macOS Sonoma implementations.

Affected Version(s)

macOS 0 < 14.8.8

macOS 0 < 15.7.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.