6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Description
Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
Basic Information
ID
CVE-2026-28909
Source
apple
Published
Apr 30, 2026 at 22:00
Modified
May 1, 2026 at 13:57
Affected Product
Vendor
Apple
Product
macOS
Version
0.12.1
Affected Versions
Apple macOS 0.12.1