CVE-2026-28825Disclosure(apple / macos)

LOWCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple macos systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-22); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-25: 1Mentions · 2026-04-15: 1Mentions · 2026-04-22: 2Mentions · 2026-05-29: 1PoC Mentioned / Linked · 2026-04-22: 1Patch / Workaround · 2026-05-29: 1Technical Details · 2026-03-25: 1Technical Details · 2026-04-22: 103-2504-1504-2205-29
Signal classification4 categories
Disclosure
240.0%
General
120.0%
PoC
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-251
Disclosure1
2026-04-151
Disclosure1
2026-04-222
General1PoC1
2026-05-291
Patch1
Full discourse5 posts
  • thaidn@XorNinja
    PoC

    New MAD Bugs drop: we had Claude reverse Apple's macOS 26.4 SMB patch end-to-end and build a kernel PoC from just the advisory. CVE-2026-28825, heap OOB in smbfs.kext, reachable by clicking on any smb:// link in Finder, Safari, or Messages. Root cause is a missing bounds check on an attacker-controlled compress length. The fun part is in Apple's own source: the check was there. A developer wrapped it in #if 0 because Windows Server kept tripping it, left a comment about it, and shipped. The entire reversing, root-cause analysis, and PoC build was driven autonomously by Claude. We handed it the advisory URL and came back to a working panic. It even blamed Microsoft for everything. Full writeup: https://open.substack.com/pub/calif/p/mad-bugs-an-apple-kernel-bug-brought?r=26yra9&utm_campaign=post&utm_medium=web

    Post summary

    The post announces a new MAD Bugs release featuring a kernel proof‑of‑concept for CVE‑2026‑28825, detailing a heap OOB flaw in Apple’s SMB implementation, but provides no evidence of active exploitation or patching.

    23211426611.5K
    6.1K followersView on X
  • Calif@calif_io
    General

    MAD Bugs: An Apple Kernel Bug, Brought to You by Microsoft This is an autonomous N-day analysis of CVE-2026-28825. 100% reliable on macOS 26.3.2. https://open.substack.com/pub/calif/p/mad-bugs-an-apple-kernel-bug-brought?r=26yra9&utm_campaign=post&utm_medium=web

    Post summary

    The post references CVE-2026-28825 for macOS 26.3.2 but offers no further technical detail, PoC, exploit, or mitigation information.

    0231874316.1K
    5.3K followersView on X
  • Alex Rad@defendtheworld
    Patch

    @yo_yo_yo_jbo heres one: dave and i found CVE-2025-24269 which was patched incorrectly and misattributed in https://blog.calif.io/p/mad-bugs-an-apple-kernel-bug-brought as CVE-2026-28825 (a silent? patch correctly fixed with CVE-2026-28848)

    Post summary

    The note points out that CVE-2025-24269 was incorrectly attributed to CVE-2026-28825, noting a prior incorrect patch and the eventual proper fix via CVE-2026-28848.

    10010106
    2.2K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-28825 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28825 #CVE-2026-28825 #CVE   #CyberSecurity #InfoSec https://t.co/Gn9M03jcBQ

    Post summary

    This tweet announces CVE-2026-28825 with only a reference to the NVD entry and no additional technical, exploitation, or patch details.

    0000027
    137 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28825 - macOS File System Protection Out-of-Bounds Write Vulnerability Intel Report: https://ift.tt/jUBa3mt

    Post summary

    Alert alerts about CVE-2026-28825, an out-of-bounds write vulnerability in macOS File System Protection, but offers no PoC, active exploitation evidence, or patch details.

    0000044
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more