
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28866 is a symlink validation vulnerability in Apple's Clipboard component affecting iOS, iPadOS, and macOS. The flaw allows a local app to access sensitive user data by exploiting improper symlink resolution. It was discovered by Cristian Dinca (icmd.tech) and disclosed by Apple on March 24, 2026, alongside patches for all affected platforms. Affected versions include iOS and iPadOS prior to 18.7.7 and 26.4, macOS Sonoma prior to 14.8.5, macOS Sequoia prior to 15.7.5, and macOS Tahoe prior to 26.4. The vulnerability carries a CVSS v3.1 base score of 6.2 (Medium) (Apple Advisory iOS 26.4, Apple Advisory iOS 18.7.7, Feedly).
The vulnerability is classified as CWE-59 (Improper Link Resolution Before File Access, or 'Link Following'), a class of flaw where software follows symbolic links without adequately validating their targets. Specifically, the Clipboard component on affected Apple operating systems failed to properly validate symlinks before accessing files, enabling a malicious app to craft or leverage a symlink pointing to sensitive user data outside its intended access scope. Exploitation requires local access — a malicious app running on the device — but does not require elevated privileges or user interaction, as reflected in the CVSS vector (AV:L/AC:L/PR:N/UI:N). No technical write-ups or public proof-of-concept code have been identified at this time (Apple Advisory iOS 26.4, Apple Advisory macOS Tahoe 26.4).
Successful exploitation allows a malicious app to read sensitive user data that it would not normally be permitted to access, resulting in a high confidentiality impact with no effect on integrity or availability. The affected Clipboard component is present across iOS, iPadOS, and multiple macOS versions, broadening the attack surface to a wide range of Apple devices. While the vulnerability does not enable code execution or privilege escalation on its own, unauthorized access to clipboard contents could expose passwords, authentication tokens, personal messages, or other sensitive information copied by the user (Apple Advisory iOS 18.7.7, Apple Advisory macOS Sequoia 15.7.5).
/private/var/mobile/Library/Clipboard/ on iOS).unified system log via log show) showing unusual file access patterns by an app to clipboard-related paths; sandbox violation logs if partial mitigations trigger.Apple has released patches addressing CVE-2026-28866 in the following versions: iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, iPadOS 26.4, macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, and macOS Tahoe 26.4. Users and administrators should update all affected Apple devices to these versions immediately using Software Update or Apple's device management tools. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation (Apple Advisory iOS 18.7.7, Apple Advisory macOS Sequoia 15.7.5, Apple Advisory macOS Sonoma 14.8.5).
The vulnerability was part of a broader March 2026 Apple security update that addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and other platforms, which received coverage from security-focused outlets. The iOS 18.7.7 release also notably included protections against the 'DarkSword' exploit, which drew additional attention to the update cycle. No specific researcher commentary or significant social media discussion focused exclusively on CVE-2026-28866 has been identified beyond standard vulnerability aggregator coverage (Apple Advisory iOS 18.7.7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."