Junglewise Threat Intelligence

CVE-2026-28830: Apple macOS Tahoe race condition in sensitive data access

CVE-2026-28830 · Severity: medium · CVSS 4.7 · Published 2026-05-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A vulnerability in macOS Tahoe could allow a malicious application to access sensitive user data. This occurs due to a timing-related flaw where the system fails to properly validate data access requests. Users are protected by updating to the latest version of the operating system.

Technical details

A race condition exists in macOS Tahoe that can be exploited by a local application to bypass data access restrictions. The vulnerability stems from a lack of sufficient validation during concurrent operations, allowing an attacker to potentially intercept or access sensitive user information. Apple addressed this issue in macOS Tahoe 26.4 by implementing additional validation checks to ensure state consistency. Exploitation requires a malicious app to be running on the target system.

Affected products

  • Apple macOS Tahoe before 26.4

Timeline

  • 2026-03-24: patched: Fixed in macOS Tahoe 26.4
  • 2026-05-11: disclosed: CVE published by Apple

References

Related threats