A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain elevated privileges.
References
| Link | Resource |
|---|---|
| https://support.apple.com/en-us/126794 | Release Notes Vendor Advisory |
| https://support.apple.com/en-us/126795 | Release Notes Vendor Advisory |
| https://support.apple.com/en-us/126796 | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
26 Mar 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-20 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.4 |
25 Mar 2026, 21:31
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 | |
| CPE | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | |
| References | () https://support.apple.com/en-us/126794 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/126795 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/126796 - Release Notes, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| First Time |
Apple macos
Apple |
25 Mar 2026, 01:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-25 01:17
Updated : 2026-03-26 14:16
NVD link : CVE-2026-28821
Mitre link : CVE-2026-28821
CVE.ORG link : CVE-2026-28821
JSON object : View
Products Affected
apple
- macos
CWE
CWE-20
Improper Input Validation
