
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28842 is a buffer overflow vulnerability in the IOGraphics component of Apple macOS Tahoe that may result in memory corruption and unexpected application termination. It was discovered by Joseph Ravichandran (@0xjprx) of MIT CSAIL and disclosed by Apple on March 24, 2026, as part of the macOS Tahoe 26.4 security update. The vulnerability affects macOS Tahoe versions prior to 26.4. It carries an estimated CVSS v3.1 base score of 7.5 (High), reflecting its network-accessible, unauthenticated attack vector with high availability impact (Apple Advisory).
The root cause is insufficient bounds checking in the IOGraphics subsystem of macOS, classified as CWE-120 (Classic Buffer Overflow) and CWE-122 (Heap-based Buffer Overflow). An unauthenticated remote attacker can trigger the overflow over the network without user interaction, causing memory corruption in the affected process. Apple addressed the issue by implementing improved bounds checks in macOS Tahoe 26.4 (Apple Advisory). No public technical write-up or proof-of-concept code has been identified at this time.
Successful exploitation results in memory corruption and unexpected termination of affected applications, constituting a denial-of-service condition. The primary impact is on availability — confidentiality and integrity are not directly affected based on the CVSS assessment. Because the attack requires no authentication and no user interaction, it can be triggered remotely against any vulnerable macOS Tahoe system exposed to network traffic (Apple Advisory).
Apple has released a patch in macOS Tahoe 26.4, available as of March 24, 2026. Users and administrators should update to macOS Tahoe 26.4 or later immediately. No configuration-based workaround has been published; upgrading is the only recommended remediation (Apple Advisory).
The vulnerability was part of a broader Apple security update for macOS Tahoe 26.4 that addressed over 140 vulnerabilities across Apple platforms, which received general coverage from security news aggregators and community trackers. The CIS noted the update in its advisory on multiple vulnerabilities in Apple products. No specific researcher commentary or notable social media discussion focused exclusively on CVE-2026-28842 has been identified (Apple Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."