CVE-2026-28862
macOS vulnerability analysis and mitigation

Overview

CVE-2026-28862 is a privacy vulnerability in the Phone component of Apple macOS that allows an app to access user-sensitive data through insufficient private data redaction in log entries. It was disclosed and patched on March 24, 2026, affecting macOS Sonoma (14.0–14.8.5), macOS Sequoia (15.0–15.7.5), and macOS Tahoe (26.0–26.4). The vulnerability was discovered by Kun Peeks (@SwayZGl1tZyyy) and reported to Apple. It carries an estimated CVSS v3.1 base score of 5.3 (Medium) (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).

Technical details

The root cause is classified as CWE-284 (Improper Access Control), specifically a failure to adequately redact private data from system log entries within the Phone component. Apple's fix involved improved private data redaction for log entries. The vulnerability does not require user interaction or special privileges to trigger, as log entries containing sensitive data may be accessible to apps running on the system. No public technical write-ups or proof-of-concept code have been identified (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).

Impact

Successful exploitation allows a malicious app to read user-sensitive data — specifically phone-related information — that is inadvertently written to system log entries without proper redaction. The primary impact is a confidentiality breach, as sensitive user data (such as phone call metadata or contact information) could be exposed to unauthorized apps. Integrity and availability are not directly affected by this vulnerability (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).

Mitigation and workarounds

Apple has released patches addressing CVE-2026-28862 across all affected macOS branches. Users should update to macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, or macOS Tahoe 26.4 or later, depending on their current version. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).

Community reactions

The vulnerability was part of a broader Apple security update in March 2026 that addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS. CIS published an advisory noting multiple vulnerabilities in Apple products could allow for privilege escalation. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-28862 has been identified beyond standard patch coverage.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management