CVE-2026-28823

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
25/03/2026
Last modified:
25/03/2026

Description

A path handling issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.4. An app with root privileges may be able to delete protected system files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 26.0 (including) 26.4 (excluding)


References to Advisories, Solutions, and Tools