Junglewise Threat Intelligence

CVE-2026-28840: Apple macOS privilege escalation to root via permissions issue

CVE-2026-28840 · Severity: high · CVSS 7.8 · Published 2026-05-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to gain full administrative (root) control over a computer. This would allow the app to bypass standard security protections, access all user data, and modify system settings. Users should update to the latest versions of macOS Sequoia, Sonoma, or Tahoe to resolve this issue.

Technical details

A permissions vulnerability exists in macOS that allows for local privilege escalation. The flaw stems from insufficient restrictions within the operating system's permission handling logic. A malicious application installed on the system can exploit this issue to gain root privileges, effectively bypassing the system's security model. Apple addressed the vulnerability by implementing additional restrictions and improved validation. The fix is available in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.4.

Affected products

  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.4

Timeline

  • 2026-03-24: patched: Initial patch released for macOS Tahoe 26.4
  • 2026-05-11: patched: Patches released for macOS Sequoia 15.7.7 and macOS Sonoma 14.8.7
  • 2026-05-11: disclosed: Public advisory published by Apple and NVD record created

References

Related threats