PatchSiren cyber security CVE debrief
CVE-2026-28838 Apple CVE debrief
Apple addressed a macOS permissions issue by adding additional sandbox restrictions. According to the vendor description, an app may be able to break out of its sandbox. Apple lists fixes for macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, and macOS Tahoe 26.4. NVD rates the issue Medium severity (CVSS 5.3).
- Vendor
- Apple
- Product
- CVE-2026-28838
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-25
- Original CVE updated
- 2026-05-10
- Advisory published
- 2026-03-25
- Advisory updated
- 2026-05-10
Who should care
macOS administrators, security teams, and users running affected macOS releases should pay attention, especially if they rely on sandboxing to contain third-party or less-trusted apps.
Technical summary
The issue is described as a permissions problem in macOS sandbox enforcement. Apple says it was fixed with additional sandbox restrictions. NVD maps affected macOS versions to Sonoma releases before 14.8.5, Sequoia releases before 15.7.5, and Tahoe releases before 26.4. The NVD CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, which indicates a network-capable issue requiring no privileges or user interaction, with low confidentiality impact and no integrity or availability impact scored by NVD.
Defensive priority
Medium. The issue is publicly disclosed, vendor-fixed, and rated CVSS 5.3, but the impact is limited to sandbox escape rather than a full-system compromise in the published advisory.
Recommended defensive actions
- Install the Apple updates that include macOS Sonoma 14.8.5, Sequoia 15.7.5, or Tahoe 26.4 as appropriate for your device.
- Prioritize systems that run untrusted or third-party apps, since sandbox boundaries are the affected control.
- Confirm fleet compliance against the fixed macOS versions and remediate any older releases listed by NVD.
- Review application allowlists and containment assumptions, but do not rely on sandboxing alone for high-risk workloads.
Evidence notes
This debrief is based on the CVE record, NVD metadata, and Apple vendor references. The CVE description says: “A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.” NVD assigns CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N and lists Apple support references as vendor advisories.
Official resources
-
CVE-2026-28838 CVE record
CVE.org
-
CVE-2026-28838 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Release Notes, Vendor Advisory
CVE-2026-28838 was published on 2026-03-25 and modified on 2026-05-10. Apple’s advisory states the issue is fixed in macOS Sonoma 14.8.5, Sequoia 15.7.5, and Tahoe 26.4.