CVE-2026-28910General(apple / macos)

LOWCVSS 3.3 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple macos systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files.

2.3/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 19 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • General: 11 classified signals
  • Disclosure: 5 classified signals
  • Peaked 8d ago at 3 mentions (2026-05-22); latest day: 1
  • 19 total mentions across 11 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline19 mentions / 11d
01223Mentions · 2026-05-20: 1Mentions · 2026-05-21: 1Mentions · 2026-05-22: 3Mentions · 2026-05-23: 1Mentions · 2026-05-24: 2Mentions · 2026-05-28: 3Mentions · 2026-05-29: 3Mentions · 2026-05-31: 2Mentions · 2026-06-01: 1Mentions · 2026-08-23: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-08-23: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-31: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-31: 2Technical Details · 2026-08-23: 105-2005-2105-2205-2305-2405-2805-2905-3106-0108-2308-27
Signal classification4 categories
General
1157.9%
Disclosure
526.3%
Patch
210.5%
False Positive
15.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-201
False Positive1
2026-05-211
General1
2026-05-223
Disclosure3
2026-05-231
Patch1
2026-05-242
Disclosure1General1
2026-05-283
General3
2026-05-293
General3
2026-05-312
General1Patch1
2026-06-011
General1
2026-08-231
Disclosure1
2026-08-271
General1
Full discourse19 posts
  • Mysk 🇨🇦🇩🇪@mysk_co
    General

    We had lengthy discussions explaining the bug to Apple. It was clear to us the bug was new to Apple Product Security. After 5 months, they informed us that the report was treated as a duplicate and it was addressed. We just got this update for CVE-2026-28910: No bounty https://t.co/rW6mktYn0E

    Post summary

    The user was informed that CVE-2026-28910 was treated as a duplicate by Apple and addressed, with no bounty awarded or technical details disclosed.

    193841.6K1731.6M
    20.8K followersView on X
  • Blackstorm Security@blackstormsecbr
    Disclosure

    CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility: https://mysk.blog/2026/05/19/cve-2026-28910/ #cybersecurity #macOS #vulnerability #cve #exploitation https://t.co/GMMZ23kACC

    Post summary

    The tweet announces CVE-2026-28910, a macOS vulnerability, and provides a blog link for more information.

    014089535.7K
    2.1K followersView on X
  • Tony Gorez@tonygo_
    General

    Awesome write-up by @mysk_co ! Top notch! https://mysk.blog/2026/05/19/cve-2026-28910/

    Post summary

    The text merely refers to a blog post about CVE-2026-28910 without providing any substantive technical, exploit, or mitigation details.

    18032253.5K
    1.2K followersView on X
  • Zhongquan Li@Guluisacat
    General

    CVE-2026-28910 just saw the CVE information has been updated. Im the first one who found this vulnerability, on 5/8/25, five months before you did. And the impact was underestimated, it could do more things than your PoC.Easily weaponized. Keep calm. Your post made it sound like I had stolen your research. If you wanna verify the timing of other reports, DM them instead of doing something like this. Not geeky.

    Post summary

    The user claims they discovered CVE-2026-28910 five months before the referenced investigation and that the impact was underestimated, but no concrete technical details, exploit code, or patch information are provided.

    321461115.7K
    950 followersView on X
  • Mysk 🇨🇦🇩🇪@mysk_co
    General

    Had they said that to us within the first weeks of submitting the report, it would be totally fine. Check the report timeline: October 17, 2025 - Mysk submits report to Apple. April 9, 2026 - Apple responds that a CVE will be assigned shortly, and credit will be given in an upcoming security advisory. Also notes that Mysk’s report overlapped with a previously reported issue and was handled as a duplicate. https://mysk.blog/2026/05/19/cve-2026-28910/#report-timeline

    Post summary

    The text provides a reporting timeline for CVE‑2026‑28910 without mentioning proof of concept, exploit availability, active exploitation, or mitigation steps.

    2003709.2K
    20.8K followersView on X
  • Mysk 🇨🇦🇩🇪@mysk_co
    General

    @TechX1320 This report took Apple around 6 moths to tell us it was a duplicate. So we thought it was a tie. Today and after 7 months we learned for the first time someone else was first. Link to the timeline: https://mysk.blog/2026/05/19/cve-2026-28910/#report-timeline

    Post summary

    The tweet references the timeline of CVE‑2026‑28910, noting Apple’s delayed duplicate acknowledgment and that the blog shows someone else discovered it first, but it contains no evidence of exploits, patches, or PoC details.

    01124410.9K
    20.8K followersView on X
  • Clandestine@akaclandestine
    Disclosure

    CVE-2026-28910: Breaking the macOS App Sandbox, TCC and Code Signing with Archive Utility https://core-jmp.org/2026/05/cve-2026-28910-macos-archive-utility-sandbox-tcc-app-hijacking/

    Post summary

    The text announces CVE-2026-28910, labeling it as a macOS vulnerability that undermines sandboxing and code signing via Archive Utility, without detailing proofs of concept, active exploitation, or remediation.

    0201482.4K
    62.5K followersView on X
  • Mysk 🇨🇦🇩🇪@mysk_co
    General

    Related work on app containers: https://mysk.blog/2026/05/19/cve-2026-28910/

    Post summary

    The text references a blog post about CVE-2026-28910 but provides no actionable indicators such as PoC, exploit, patch, or active exploitation details.

    0201366.5K
    20.8K followersView on X
  • Mysk 🇨🇦🇩🇪@mysk_co
    General

    @Dark__val @Don_Felipe007 Yes, if they had shared that information with us as soon as they understood the bug and were able to reproduce it, it would have been fair. It took them 4-5 months. Here's the timeline of the report: https://mysk.blog/2026/05/19/cve-2026-28910/#report-timeline

    Post summary

    The tweet shares a timeline for CVE‑2026‑28910 but offers no technical details, PoC, exploit, or patch information.

    000170739
    20.8K followersView on X
  • JD Work@HostileSpectrum
    General

    The very fact that there were reportedly bug collisions on CVE-2026-28910 as of at least Oct ‘25, and not widely understood until the March - April ‘26 timeframe, is one of the most important recent exemplar cases in warning failure in vulnerability intelligence. But more important is that such collisions across many attack surfaces are almost certainly rather frequent, and rarely priced into response and policy.

    Post summary

    The text highlights bug collisions on CVE-2026-28910, noting that such collisions are common yet often overlooked in vulnerability intelligence and response planning.

    03080836
    9.2K followersView on X
  • Sooraj@iAnonymous3000
    Patch

    This is a macOS Archive Utility bug, CVE-2026-28910 (not a Brave issue) and Apple already patched it in 26.4. The attack swaps a signed app’s executable on disk and slips past code signing, which guards App Store and directly downloaded apps the same way. So where you got the browser isn’t the variable. It also only fires after the victim runs the attacker’s shell script and gets tricked into a drag and drop. What do you mean by “Brave can be easily hijacked”? How?

    Post summary

    The text reports that Apple has patched CVE-2026-28910 in macOS 26.4, explains the attack mechanism, but does not mention a PoC or active exploitation.

    200801.6K
    15.1K followersView on X
  • Mysk 🇨🇦🇩🇪@mysk_co
    Disclosure

    CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility https://mysk.blog/2026/05/19/cve-2026-28910/

    Post summary

    The text announces a newly discovered CVE (CVE‑2026‑28910) that allegedly compromises macOS sandboxing and app hijacking via Archive Utility, but it provides no detail on exploitation, patches, or PoC.

    00060969
    20.8K followersView on X
  • Mickey Jin@patch1t
    False Positive

    @mysk_co The CVE-2026-28910 requires the access to a protected plist file first, this shouldn’t be considered as a real vulnerability, in my humble opinion.

    Post summary

    The post argues that CVE-2026-28910 is not a genuine vulnerability, providing a brief technical detail (access to a protected plist file) but no PoC, exploit code, patch, or evidence of active exploitation.

    10031472
    5.3K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility http://dlvr.it/TV7lVS #cyber #threathunting #infosec

    Post summary

    The tweet discloses CVE-2026-28910 as a macOS sandbox bypass via Archive Utility, providing technical detail but no mention of active exploitation or patches.

    010121.9K
    57.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-45585 2 - CVE-2025-36911 3 - CVE-2026-31525 4 - CVE-2026-0257 5 - CVE-2026-28910 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without providing any additional details on exploitation, patches, or technical attributes, indicating a generic awareness announcement.

    00011154
    1.7K followersView on X
  • Bob Burrough@bob_burrough
    General

    Apple peeps...CVE-2026-28910...you should reward the effort expended by the 3rd party for helping secure your products...not whether the report is new to you. ...especially when the issue hasn't yet been published. Even reviewing the duplicate helps you understand the bug.

    Post summary

    The message references CVE‑2026‑28910 and encourages rewarding third‑party researchers, but it offers no technical or exploit details.

    00011489
    5.6K followersView on X
  • MiroSilva 🇧🇷 🇺🇸@Miro_Silva_BR
    General

    DuckDuckGo no Mac App Store realmente parece a opção mais segura contra esse tipo de hijacking de executáveis, mas o problema do Archive Utility (CVE-2026-28910) mostra como o macOS ainda tem brechas sérias para apps baixados direto do site. Porém, vale lembrar o trade-off: atualizações de segurança no App Store dependem da aprovação da Apple, o que pode atrasar patches urgentes. No fim, é escolher entre risco de phishing/hijacking ou possível demora em correções. Apple precisa resolver isso de vez no nível do sistema.

    Post summary

    The post points out macOS’s Archive Utility vulnerability (CVE‑2026‑28910) and the risk it poses, without providing a PoC, exploit code, or patch details, and without evidence of active exploitation.

    00000135
    1.2K followersView on X
  • Steve Puluka@spuluka
    Patch

    Interesting deep dive on the @Apple MacOS CVE-2026-28910 patched last month that allowed full file system access. https://mysk.blog/2026/05/19/cve-2026-28910/

    Post summary

    The post highlights a deep dive into Apple macOS CVE‑2026‑28910, noting that it was patched recently and originally allowed full file system access.

    0000086
    1.3K followersView on X
  • Meister des Apfels@appletechnikbl
    Disclosure

    Sicherheitslücke CVE-2026-28910 in macOS Tahoe: Apples Archive Utility hebelte Sandbox und TCC-Schutz aus – fünf Monate lang. Mehr erfahrt Ihr hier >> https://wp.me/p7za8I-LSd

    Post summary

    The post announces CVE‑2026‑28910, noting that Apple’s Archive Utility disabled sandbox and TCC protection in macOS Tahoe for five months, and provides a link to further details.

    0000064
    878 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more