
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28862 is a privacy vulnerability in the Phone component of Apple macOS that allows an app to access user-sensitive data through insufficient private data redaction in log entries. It was disclosed and patched on March 24, 2026, affecting macOS Sonoma (14.0–14.8.5), macOS Sequoia (15.0–15.7.5), and macOS Tahoe (26.0–26.4). The vulnerability was discovered by Kun Peeks (@SwayZGl1tZyyy) and reported to Apple. It carries an estimated CVSS v3.1 base score of 5.3 (Medium) (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).
The root cause is classified as CWE-284 (Improper Access Control), specifically a failure to adequately redact private data from system log entries within the Phone component. Apple's fix involved improved private data redaction for log entries. The vulnerability does not require user interaction or special privileges to trigger, as log entries containing sensitive data may be accessible to apps running on the system. No public technical write-ups or proof-of-concept code have been identified (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).
Successful exploitation allows a malicious app to read user-sensitive data — specifically phone-related information — that is inadvertently written to system log entries without proper redaction. The primary impact is a confidentiality breach, as sensitive user data (such as phone call metadata or contact information) could be exposed to unauthorized apps. Integrity and availability are not directly affected by this vulnerability (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).
Apple has released patches addressing CVE-2026-28862 across all affected macOS branches. Users should update to macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, or macOS Tahoe 26.4 or later, depending on their current version. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).
The vulnerability was part of a broader Apple security update in March 2026 that addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS. CIS published an advisory noting multiple vulnerabilities in Apple products could allow for privilege escalation. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-28862 has been identified beyond standard patch coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."