Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1247 articles · 101974 vulns · 38/41 feeds (7d)
← Back to list
5.5
CVE-2026-28892PATCHED
apple · macos

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of t

Description

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.

Affected Products

VendorProductVersions
applemacos< 14.8.5, < 15.7.5, < 26.4, < 18.7.7

References

  • https://support.apple.com/en-us/126794(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/126795(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/126796(Release Notes, Vendor Advisory)

Related News (1 articles)

Tier B
CCCS Canada3h ago
Apple security advisory (AV26-275)
→ No new info (linked only)
CVSS 3.15.5 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
14.8.515.7.526.4
PublishedMar 25, 2026
Last enriched3h agov2
Trending Score23
Source articles1
Independent1
Info Completeness9/14
Missing: epss, cwe, kev, exploit, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20700EXPKEV
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memo
Trending: 97
PRE-CVEEXP
Coruna iPhone Hacking Toolkit Exploiting iOS Vulnerabilities
Trending: 38
MEDIUMCVE-2026-20665
This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watc
Trending: 14
MEDIUMCVE-2026-20664
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lea
Trending: 14
MEDIUMCVE-2026-20643
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and
Trending: 14

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 25, 2026
Patch Available
Mar 27, 2026
Discovered by ZDM
Apr 1, 2026
Updated: affectedVersions, iocs
Apr 2, 2026

Version History

v2
Last enriched 3h ago
v2Tier B3h ago

Added new affected versions for iOS and iPadOS, marked exploit as available and actively exploited, and included IOC related to DarkSword exploit kit.

affectedVersionsiocs
via CCCS Canada
v123h ago

Initial creation