cbcvebase.
CVE-2026-28954
published 2026-05-11

CVE-2026-28954: A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.39%
31.3th percentile
A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted disk image may bypass Gatekeeper checks.

Affected

9 ranges
VendorProductVersion rangeFixed in
appleios_and_ipados< 18.7.918.7.9
appleipados< 18.7.918.7.9
appleiphone_os< 18.7.918.7.9
applemacos< 14.8.714.8.7
applemacos< 15.7.715.7.7
applemacos< 26.526.5
applemacos>= 14.0 < 14.8.714.8.7
applemacos>= 15.0 < 15.7.715.7.7
applemacos>= 26.0 < 26.526.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.