CVE-2026-28866
macOS vulnerability analysis and mitigation

Overview

CVE-2026-28866 is a symlink validation vulnerability in Apple's Clipboard component affecting iOS, iPadOS, and macOS. The flaw allows a local app to access sensitive user data by exploiting improper symlink resolution. It was discovered by Cristian Dinca (icmd.tech) and disclosed by Apple on March 24, 2026, alongside patches for all affected platforms. Affected versions include iOS and iPadOS prior to 18.7.7 and 26.4, macOS Sonoma prior to 14.8.5, macOS Sequoia prior to 15.7.5, and macOS Tahoe prior to 26.4. The vulnerability carries a CVSS v3.1 base score of 6.2 (Medium) (Apple Advisory iOS 26.4, Apple Advisory iOS 18.7.7, Feedly).

Technical details

The vulnerability is classified as CWE-59 (Improper Link Resolution Before File Access, or 'Link Following'), a class of flaw where software follows symbolic links without adequately validating their targets. Specifically, the Clipboard component on affected Apple operating systems failed to properly validate symlinks before accessing files, enabling a malicious app to craft or leverage a symlink pointing to sensitive user data outside its intended access scope. Exploitation requires local access — a malicious app running on the device — but does not require elevated privileges or user interaction, as reflected in the CVSS vector (AV:L/AC:L/PR:N/UI:N). No technical write-ups or public proof-of-concept code have been identified at this time (Apple Advisory iOS 26.4, Apple Advisory macOS Tahoe 26.4).

Impact

Successful exploitation allows a malicious app to read sensitive user data that it would not normally be permitted to access, resulting in a high confidentiality impact with no effect on integrity or availability. The affected Clipboard component is present across iOS, iPadOS, and multiple macOS versions, broadening the attack surface to a wide range of Apple devices. While the vulnerability does not enable code execution or privilege escalation on its own, unauthorized access to clipboard contents could expose passwords, authentication tokens, personal messages, or other sensitive information copied by the user (Apple Advisory iOS 18.7.7, Apple Advisory macOS Sequoia 15.7.5).

Exploitation steps

  1. Develop or distribute a malicious app: An attacker creates a malicious iOS, iPadOS, or macOS application and distributes it to a target device (e.g., via sideloading, enterprise distribution, or the App Store if policy controls are bypassed).
  2. Create a malicious symlink: The app creates a symbolic link within its accessible file system space that points to a sensitive file or directory outside its sandbox (e.g., clipboard data storage locations).
  3. Trigger Clipboard access: The app invokes Clipboard-related APIs or system calls that follow the symlink without adequate validation, causing the OS to resolve the symlink and grant the app access to the target sensitive data.
  4. Exfiltrate sensitive data: The app reads the resolved file contents — which may include clipboard data such as passwords, tokens, or personal information — and transmits it to an attacker-controlled server or stores it for later retrieval (Apple Advisory iOS 26.4, Apple Advisory macOS Sonoma 14.8.5).

Indicators of compromise

  • File System: Unexpected symbolic links created within app sandbox directories pointing to locations outside the app's permitted scope; symlinks targeting clipboard or user data directories (e.g., /private/var/mobile/Library/Clipboard/ on iOS).
  • Logs: System logs (e.g., unified system log via log show) showing unusual file access patterns by an app to clipboard-related paths; sandbox violation logs if partial mitigations trigger.
  • Process: Apps making unexpected or repeated file system calls to clipboard storage paths without corresponding user-initiated paste actions; apps accessing sensitive data directories not consistent with their declared entitlements.

Mitigation and workarounds

Apple has released patches addressing CVE-2026-28866 in the following versions: iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, iPadOS 26.4, macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, and macOS Tahoe 26.4. Users and administrators should update all affected Apple devices to these versions immediately using Software Update or Apple's device management tools. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation (Apple Advisory iOS 18.7.7, Apple Advisory macOS Sequoia 15.7.5, Apple Advisory macOS Sonoma 14.8.5).

Community reactions

The vulnerability was part of a broader March 2026 Apple security update that addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and other platforms, which received coverage from security-focused outlets. The iOS 18.7.7 release also notably included protections against the 'DarkSword' exploit, which drew additional attention to the update cycle. No specific researcher commentary or significant social media discussion focused exclusively on CVE-2026-28866 has been identified beyond standard vulnerability aggregator coverage (Apple Advisory iOS 18.7.7).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management