
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28823 is a path handling vulnerability in Apple macOS Tahoe that allows an app with root privileges to delete protected system files. The flaw was addressed with improved validation and disclosed by Apple on March 24, 2026, as part of the macOS Tahoe 26.4 security update. It affects macOS Tahoe versions prior to 26.4. The vulnerability was discovered by Ryan Dowd (@_rdowd) and is classified as Medium severity with an estimated CVSS v3.1 base score of 4.9 (Apple Advisory, Feedly).
The vulnerability is rooted in improper path validation within the Admin Framework component of macOS Tahoe, classified as CWE-284 (Improper Access Control). A malicious application running with root privileges can exploit insufficient path handling logic to bypass protections that normally prevent deletion of critical system files. Exploitation requires the attacker to already possess root-level access on the target system, limiting the attack surface to post-compromise or privileged-app scenarios. No public proof-of-concept or detailed technical write-up has been identified at this time (Apple Advisory, Feedly).
Successful exploitation allows a root-privileged application to delete protected system files that would otherwise be shielded by macOS integrity protections. This could result in system instability, denial of service, or the removal of security-critical components, potentially undermining the integrity of the operating system. While confidentiality and availability impacts are limited, the ability to tamper with protected system files poses a meaningful integrity risk, particularly in scenarios where an attacker has already achieved root access and seeks to persist or cover tracks (Apple Advisory, Feedly).
Apple has addressed this vulnerability in macOS Tahoe 26.4, released on March 24, 2026. Users and administrators should update affected macOS Tahoe systems to version 26.4 or later as the primary remediation. As additional hardening measures, organizations should restrict root-level privileges to only trusted and verified applications, and deploy file integrity monitoring tools to detect unauthorized deletion or modification of protected system files (Apple Advisory).
The vulnerability was noted in broader coverage of Apple's March 2026 security updates, which addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS. The SANS Internet Storm Center and CIS both published advisories referencing the update batch. No specific researcher commentary or significant social media discussion focused exclusively on CVE-2026-28823 has been identified (SANS ISC, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."