PT-2026-39777 · Apple · Macos Tahoe+1

·

CVE-2026-28910

·

Published

2026-03-24

·

Updated

2026-08-27

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS Tahoe versions prior to 26.4
Description A flaw in the macOS Archive Utility allows a malicious application to access arbitrary files due to insufficient permissions checking. The issue can be exploited if a user executes an attacker-controlled shell script and is tricked into performing a drag-and-drop action. This process allows an attacker to swap a signed application's executable on disk, bypassing code signing protections that typically guard applications downloaded from the App Store or directly from the web.
Recommendations Update macOS Tahoe to version 26.4.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28910

Affected Products

Apple Macos
Macos Tahoe