• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-28912: local privilege escalation in Apple macOS

Local users can elevate their privileges on macOS due to a logic issue; this vulnerability is tracked as CVE-2026-28912. Affected releases include macOS Sonoma 14.x before 14.8.7, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires local access with low privileges (no user interaction is required) and can yield high confidentiality, integrity, and availability impacts.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.8HIGH
EPSS
0.00173
CWE
CWE-693
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so update systems promptly; Apple published fixes for the affected branches. Prioritise patching hosts where untrusted local users have access.

What is CVE-2026-28912?

Local users can elevate their privileges on macOS due to a logic issue; this vulnerability is tracked as CVE-2026-28912. Affected releases include macOS Sonoma 14.x before 14.8.7, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires local access with low privileges (no user interaction is required) and can yield high confidentiality, integrity, and availability impacts.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
14.xbefore 14.8.714.8.7
15.xbefore 15.7.815.7.8
26.xbefore 26.626.6

Is CVE-2026-28912 being exploited?

Public exploit code is available.

How to fix CVE-2026-28912

  1. Apply Apple’s updates: upgrade to 14.8.7, 15.7.8, or 26.6 as appropriate.
  2. Restrict local account access and remove unnecessary privileged group memberships.
  3. Monitor system logs for unexpected privilege-related activity and new local accounts.
  4. Follow Apple’s guidance for hardening and apply additional vendor mitigations if listed.

Frequently asked questions

Is CVE-2026-28912 being actively exploited?

Public exploit code is available for CVE-2026-28912.

Which macOS versions are affected by CVE-2026-28912?

macOS Sonoma 14.x before 14.8.7, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6 are affected.

Is there a patch for CVE-2026-28912?

Yes, Apple fixed the issue in macOS 14.8.7, 15.7.8, and 26.6.

Does CVE-2026-28912 require authentication?

Exploitation requires local access with low privileges; no additional user interaction is required.

References