CVE-2026-28961

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.
Configurations

Configuration 1 (hide)

cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

27 Jul 2026, 21:16

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/128071 -
  • () https://support.apple.com/en-us/128072 -
Summary (en) This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information. (en) This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.

14 May 2026, 14:01

Type Values Removed Values Added
References () https://support.apple.com/en-us/127115 - () https://support.apple.com/en-us/127115 - Release Notes, Vendor Advisory
First Time Apple macos
Apple
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

13 May 2026, 14:17

Type Values Removed Values Added
CWE CWE-522
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6

11 May 2026, 21:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 21:18

Updated : 2026-07-27 21:16


NVD link : CVE-2026-28961

Mitre link : CVE-2026-28961

CVE.ORG link : CVE-2026-28961


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-522

Insufficiently Protected Credentials