Skip to content
AppleCVE-2026-28849

Apple macOS: authentication bypass by spoofing

Medium5.5CVE-2026-28849 · Published Jul 27, 2026 · updated Aug 25, 2026

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

Apple advisory

Affected versions

PackageAffectedFixed in
macOS
Product
< 14.8.814.8.8
< 15.7.815.7.8
< 26.526.5
Details and references

More Apple advisories

All Apple
Advisory
Apple iOS and iPadOS: out-of-bounds write
Critical9.8Jul 27
Apple iOS and iPadOS: out-of-bounds write
Critical9.8Jul 27
Apple iOS and iPadOS: buffer overflow
Critical9.8Jul 27
Apple iOS and iPadOS: out-of-bounds write
Critical9.8Jul 27
Apple iOS and iPadOS: integer overflow
Critical9.8Jul 27
A memory initialization issue was addressed with improved memory handling
Critical9.8Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.