PT-2026-39777 · Apple · Macos Tahoe+1

Guluisacat

+4

·

Published

2026-03-24

·

Updated

2026-05-24

·

CVE-2026-28910

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS Tahoe versions prior to 26.4
Description A flaw in the Archive Utility allows a malicious application to bypass the App Sandbox data containers, Transparency, Consent, and Control (TCC), and code signing. This can lead to the hijacking of applications and provide unauthorized access to arbitrary files across the full file system. The issue stems from insufficient permissions checking.
Recommendations Update to macOS Tahoe 26.4.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-28910

Affected Products

Apple Macos
Macos Tahoe