CVE-2026-28867
macOS vulnerability analysis and mitigation

Overview

CVE-2026-28867 is a kernel information disclosure vulnerability affecting multiple Apple operating systems that allows a local app to leak sensitive kernel state. Discovered and reported by Jian Lee (@speedyfriend433), it was disclosed and patched on March 24, 2026. Affected platforms include iOS (before 18.7.7 and before 26.4), iPadOS (before 18.7.7 and before 26.4), macOS Sequoia (before 15.7.5), macOS Tahoe (before 26.4), tvOS (before 26.4), visionOS (before 26.4), and watchOS (before 26.4). The vulnerability carries a CVSS v3.1 base score of 6.2 (Medium) (Apple Advisory iOS 26.4, Apple Advisory iOS 18.7.7, Apple Advisory macOS Tahoe).

Technical details

The vulnerability resides in the Apple kernel (XNU) and is classified as an improper authentication or access control issue (the fix was described as "improved authentication"), which allowed an unprivileged local application to access and read sensitive kernel state that should be protected. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), meaning any installed app on the device could trigger the leak without special entitlements. The vulnerability also manifests in the mDNSResponder component on iOS/iPadOS 18.7.7, suggesting the kernel state exposure may be reachable through multiple code paths. No public technical write-up or proof-of-concept code has been identified at this time (Apple Advisory iOS 18.7.7, Apple Advisory macOS Sequoia).

Impact

Successful exploitation allows a locally installed, unprivileged application to read sensitive kernel memory state, potentially exposing internal kernel data structures, pointers, or other protected information. This type of kernel information disclosure can be leveraged as a stepping stone in a multi-stage attack — for example, defeating kernel ASLR (KASLR) to facilitate a subsequent privilege escalation or kernel memory corruption exploit. The confidentiality impact is rated High with no integrity or availability impact, meaning the vulnerability alone does not grant code execution or system control, but significantly lowers the bar for chaining with other vulnerabilities (Apple Advisory iOS 26.4, Apple Advisory macOS Tahoe).

Mitigation and workarounds

Apple has released patches across all affected platforms. Users should update to the following versions or later: iOS 18.7.7 or iOS 26.4, iPadOS 18.7.7 or iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4. No configuration-based workaround is available; updating to a patched release is the only remediation. Organizations should prioritize patching on devices where sensitive data is processed, as this vulnerability could be chained with other exploits (Apple Advisory iOS 26.4, Apple Advisory iOS 18.7.7, Apple Advisory macOS Sequoia).

Community reactions

The vulnerability was part of a broader Apple security update released on March 24, 2026, that addressed over 140 vulnerabilities across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Security media noted that the iOS 18.7.7 update was later expanded to additional devices on April 1, 2026, specifically to protect users from the "DarkSword" web exploit campaign, though CVE-2026-28867 itself is a separate kernel information disclosure issue. The CIS issued an advisory noting multiple vulnerabilities in Apple products could allow for privilege escalation (Apple Advisory iOS 18.7.7).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management