CVE-2026-28893
macOS vulnerability analysis and mitigation

Overview

CVE-2026-28893 is a privacy vulnerability in Apple macOS affecting the CUPS (Common Unix Printing System) component, where a document may be written to a temporary file when using the print preview feature. The flaw was discovered by researcher Asaf Cohen and disclosed by Apple on March 24, 2026, as part of the macOS Tahoe 26.4 security update. It affects macOS Tahoe versions prior to 26.4. The vulnerability carries a CVSS v3.1 base score of 3.3 (Low), reflecting its local-only attack vector and limited integrity impact (Apple Advisory).

Technical details

The root cause is improper handling of temporary files during the print preview operation in macOS's CUPS subsystem (CWE-377: Insecure Temporary File). When a user invokes print preview, the document content is written to a temporary file in a location potentially accessible to other local users on the same system. Exploitation requires local access with standard user privileges and no user interaction beyond triggering a print preview. Apple addressed the issue with improved handling of temporary files in macOS Tahoe 26.4 (Apple Advisory).

Impact

Successful exploitation allows a local user with standard privileges to access documents written to temporary files by other users during print preview operations, constituting a file/data disclosure risk. The impact is limited to integrity (low) with no confidentiality or availability impact per the CVSS scoring, though sensitive document content could be exposed to unauthorized local users. The vulnerability is scoped to multi-user macOS systems where multiple accounts share the same machine (Apple Advisory).

Exploitation steps

  1. Local Access: Obtain a standard user account on a multi-user macOS Tahoe system running a version prior to 26.4.
  2. Trigger Print Preview: Wait for or socially engineer another user on the same system to open a document and invoke the print preview function, causing the document to be written to a temporary file.
  3. Locate Temporary File: Monitor or enumerate the system's temporary file directories (e.g., /tmp or /var/folders/) for newly created files associated with the print preview operation.
  4. Access Document Content: Read the temporary file to obtain the contents of the document that was being previewed, potentially exposing sensitive information (Apple Advisory).

Indicators of compromise

  • File System: Unexpected access or reads of temporary files in /tmp or /var/folders/ directories by processes or users other than the document owner; temporary files with print-related naming patterns created during or after print preview sessions.
  • Logs: macOS Unified Log entries showing cross-user file access events in temporary directories; audit logs (/var/audit/) recording unauthorized reads of temporary print files by non-owning users.
  • Process: Unusual file enumeration activity in temporary directories by user-space processes not associated with the printing subsystem (Apple Advisory).

Mitigation and workarounds

Apple has released a fix in macOS Tahoe 26.4, released March 24, 2026. Users should update to this version or later immediately. As a workaround on multi-user systems prior to patching, administrators can restrict permissions on temporary directories to limit cross-user file access, reducing the exposure window for temporary print files (Apple Advisory).

Community reactions

The vulnerability was included in Apple's broader March 2026 security update for macOS Tahoe, which addressed over 140 vulnerabilities across Apple platforms. Security community coverage noted the low severity of this specific issue relative to other vulnerabilities in the same release. The SANS Internet Storm Center and BeyondMachines covered the broader Apple March 2026 patch batch, with CVE-2026-28893 receiving minimal individual attention given its low CVSS score and local-only exploitability (Apple Advisory).

Additional resources

  • Apple Advisory — Official Apple security advisory for macOS Tahoe 26.4
  • SANS ISC Diary — SANS Internet Storm Center coverage of Apple March 2026 updates
  • Full Disclosure List — Seclists Full Disclosure post for March 2026 Apple updates
  • CIS Advisory — CIS advisory on multiple Apple vulnerabilities

SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management