CVE-2026-28838
published 2026-03-25CVE-2026-28838: A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.47%
38.2th percentile
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 14.8.5 | 14.8.5 |
| apple | macos | < 15.7.5 | 15.7.5 |
| apple | macos | < 26.4 | 26.4 |
| apple | macos | >= 14.0 < 14.8.5 | 14.8.5 |
| apple | macos | >= 15.0 < 15.7.5 | 15.7.5 |
| apple | macos | >= 26.0 < 26.4 | 26.4 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7j45-7q44-56w8: A permissions issue was addressed with additional sandbox restrictions
ghsa_unreviewed·2026-03-25
CVE-2026-28838 [MEDIUM] GHSA-7j45-7q44-56w8: A permissions issue was addressed with additional sandbox restrictions
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
Red Hat
GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling
vendor_redhat·2026-03-13·CVSS 7.8
CVE-2026-2923 [HIGH] CWE-787 GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling
GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling
GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the handling of coordinates. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28838.
A flaw was found in GStreamer. This out-of-bounds write vulne
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-28838 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28838 [HIGH] CVE-2026-28838 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28838 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulne
Bugzilla
CVE-2026-2923 GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling
bugzilla·2026-03-13·CVSS 7.8
CVE-2026-2923 [HIGH] CVE-2026-2923 GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling
CVE-2026-2923 GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling
GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the handling of coordinates. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28838.
Discussion:
This issue has been addressed in
2026-03-25
Published