LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-28924

apple · macos

Published
CVSS7.5
Severityhigh
WeaknessCWE-362
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access Contacts without user consent.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-28924

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-28924.