CVE 6.2 MEDIUM

CVE-2026-28866_CVE-2026-28866

6.2 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

Basic Information

ID CVE-2026-28866
Source apple
Published Mar 25, 2026 at 00:31
Modified Apr 2, 2026 at 18:11

Affected Product

Vendor Apple
Product iOS and iPadOS
Affected Versions Apple iOS and iPadOS 0
Apple iOS and iPadOS 0
Apple macOS 0
Apple macOS 0
Apple macOS 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.