PT-2026-39777 · Apple · Macos Tahoe+1
Guluisacat
+4
·
Published
2026-03-24
·
Updated
2026-05-24
·
CVE-2026-28910
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
macOS Tahoe versions prior to 26.4
Description
A flaw in the Archive Utility allows a malicious application to bypass the App Sandbox data containers, Transparency, Consent, and Control (TCC), and code signing. This can lead to the hijacking of applications and provide unauthorized access to arbitrary files across the full file system. The issue stems from insufficient permissions checking.
Recommendations
Update to macOS Tahoe 26.4.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Macos Tahoe