
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28892 is a permissions issue in the macOS Diagnostics component that allows a local app to modify protected parts of the file system. The vulnerability was addressed by removing the vulnerable code, and patches were released on March 24, 2026. Affected versions include macOS Sonoma 14.0–14.8.4, macOS Sequoia 15.0–15.7.4, and macOS Tahoe 26.0–26.3. It carries a CVSS v3.1 base score of 5.5 (Medium), reflecting a local attack vector with low privileges required and high integrity impact (Apple Sonoma Advisory, Apple Sequoia Advisory, Apple Tahoe Advisory). The vulnerability was discovered by 风沐云烟 (@binary_fmyy) and Minghao Lin (@Y1nKoc).
The root cause is a permissions issue (CWE-732: Incorrect Permission Assignment for Critical Resource) in the macOS Diagnostics subsystem, where vulnerable code failed to properly enforce access controls on protected file system areas. A local app running with low privileges could exploit this flaw to write to or modify file system locations that should be restricted to higher-privilege processes. Apple resolved the issue by removing the vulnerable code entirely rather than patching the permission logic. No public technical write-up or proof-of-concept code has been identified (Apple Sonoma Advisory, Apple Sequoia Advisory, Apple Tahoe Advisory).
Successful exploitation allows a local, low-privileged app to modify protected parts of the macOS file system, compromising system integrity. This could enable an attacker to tamper with system files, configuration data, or security-relevant components that are normally off-limits to unprivileged applications. There is no direct confidentiality or availability impact based on the CVSS assessment, but unauthorized file system modifications could serve as a stepping stone for privilege escalation or persistence (Apple Sequoia Advisory, Apple Tahoe Advisory).
Apple has released patches addressing this vulnerability in macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, and macOS Tahoe 26.4, all released on March 24, 2026. Users and administrators should update to these versions or later immediately. As a precautionary measure, organizations should restrict the installation of untrusted or unvetted applications and monitor file system integrity on critical macOS systems until patches are deployed (Apple Sonoma Advisory, Apple Sequoia Advisory, Apple Tahoe Advisory).
The vulnerability was part of a broader March 2026 Apple security update that addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS, which received coverage from security news aggregators and the SANS Internet Storm Center. The CIS published an advisory noting that multiple vulnerabilities in Apple products could allow for privilege escalation. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-28892 has been identified beyond standard vulnerability tracking and aggregation (SANS ISC, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."