CVE-2026-28845
published 2026-03-25CVE-2026-28845: An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access protected user data.
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.12%
2.5th percentile
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access protected user data.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 26.4 | 26.4 |
| apple | macos | >= 26.0 < 26.4 | 26.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gffw-527m-r476: An authorization issue was addressed with improved state management
ghsa_unreviewed·2026-03-25
CVE-2026-28845 [MEDIUM] CWE-285 GHSA-gffw-527m-r476: An authorization issue was addressed with improved state management
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access protected user data.
Red Hat
GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer
vendor_redhat·2026-03-13·CVSS 7.8
CVE-2026-2922 [HIGH] CWE-787 GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer
GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer
GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the processing of video packets. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28845.
A flaw was found in GStreamer. This vulnerability allows a
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-28845 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28845 [HIGH] CVE-2026-28845 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28845 :
macOS vulnerability analysis and mitigation
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access protected user data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
LaunchServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Tech
Bugzilla
CVE-2026-2922 GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer
bugzilla·2026-03-13·CVSS 7.8
CVE-2026-2922 [HIGH] CVE-2026-2922 GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer
CVE-2026-2922 GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer
GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the processing of video packets. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28845.
Discussion:
This issue has been addressed
2026-03-25
Published