DIRAS TAKE
Urgent: public exploit code exists, so update systems promptly; Apple published fixes for the affected branches. Prioritise patching hosts where untrusted local users have access.
What is CVE-2026-28912?
Local users can elevate their privileges on macOS due to a logic issue; this vulnerability is tracked as CVE-2026-28912. Affected releases include macOS Sonoma 14.x before 14.8.7, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires local access with low privileges (no user interaction is required) and can yield high confidentiality, integrity, and availability impacts.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple macOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 14.x | before 14.8.7 | 14.8.7 |
| 15.x | before 15.7.8 | 15.7.8 |
| 26.x | before 26.6 | 26.6 |
Is CVE-2026-28912 being exploited?
Public exploit code is available.
How to fix CVE-2026-28912
- Apply Apple’s updates: upgrade to 14.8.7, 15.7.8, or 26.6 as appropriate.
- Restrict local account access and remove unnecessary privileged group memberships.
- Monitor system logs for unexpected privilege-related activity and new local accounts.
- Follow Apple’s guidance for hardening and apply additional vendor mitigations if listed.
Frequently asked questions
Is CVE-2026-28912 being actively exploited?
Public exploit code is available for CVE-2026-28912.
Which macOS versions are affected by CVE-2026-28912?
macOS Sonoma 14.x before 14.8.7, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6 are affected.
Is there a patch for CVE-2026-28912?
Yes, Apple fixed the issue in macOS 14.8.7, 15.7.8, and 26.6.
Does CVE-2026-28912 require authentication?
Exploitation requires local access with low privileges; no additional user interaction is required.
References
- nvd.nist.gov/vuln/detail/CVE-2026-28912
- cve.org/CVERecord?id=CVE-2026-28912
- support.apple.com/en-us/127117
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- All Apple CVEs on CVE Radar
- CVEs published in September 2026