CVE-2026-28914
published 2026-05-11CVE-2026-28914: A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.15%
4.5th percentile
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 14.8.8 | 14.8.8 |
| apple | macos | < 15.7.8 | 15.7.8 |
| apple | macos | < 26.5 | 26.5 |
| apple | macos | >= 26.0 < 26.5 | 26.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple macOS up to 26.4 ZIP access control (Nessus ID 330143)
vuldb·2026-07-28·CVSS 5.5
CVE-2026-28914 [MEDIUM] Apple macOS up to 26.4 ZIP access control (Nessus ID 330143)
A vulnerability was found in Apple macOS up to 26.4 and classified as critical. This affects an unknown part of the component ZIP Handler. Such manipulation leads to improper access controls.
This vulnerability is referenced as CVE-2026-28914. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-xwxw-c548-rmpj: A logic issue was addressed with improved file handling
ghsa_unreviewed·2026-05-11
CVE-2026-28914 GHSA-xwxw-c548-rmpj: A logic issue was addressed with improved file handling
A logic issue was addressed with improved file handling. This issue is fixed in macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
No detection rules found.
No public exploits indexed.
Sans Isc
Apple Patches Everything (July 2026), (Wed, Jul 29th)
blogs_sans_isc·2026-07-29·CVSS 5.5
CVE-2026-28849 [MEDIUM] Apple Patches Everything (July 2026), (Wed, Jul 29th)
Apple Patches Everything (July 2026)
Published: 2026-07-29. Last Updated: 2026-07-29 07:32:37 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.
A total of 187 vulnerabilities are addressed in this update. Many cover multiple operating systems. Apple did not label any of the vulnerabilities as already being exploited.
Three vulnerabilities that caught my interest are CVE-2026-28849, CVE-2026-28900, and CVE-2026-28914. These issues appear to be the vulnerability described in https://m
Sans Isc
Apple Patches Everything, (Mon, May 11th)
blogs_sans_isc·2026-05-11·CVSS 5.5
CVE-2025-43524 [MEDIUM] Apple Patches Everything, (Mon, May 11th)
Apple Patches Everything
Published: 2026-05-11. Last Updated: 2026-05-11 22:19:13 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
Apple today released its typical feature update across it's operating systems (iOS, iPadOS, macOS, tvOS, watchOS, vision OS). With this update, Apple patched 84 different vulnerabilities. Updates are available for the "26" series of operating systems, as well as for the previous "18" version of iOS/iPadOS, and two versions back for macOS (version 14 and 15).
None of the vulnerabilities has been exploited. The number of addressed vulnerabilities is about average compared to similar Apple updates.
Figure: Number of Vulnerabilities patched for each security update. Last one in red at the end.
iOS 26.5 and iPadOS 26.5 iOS 18.7.9 and iPadOS 18.7.9 macOS Tahoe
2026-05-11
Published