Junglewise Threat Intelligence

CVE-2026-28848: Apple macOS buffer overflow in system termination

CVE-2026-28848 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A vulnerability in macOS could allow a remote attacker to crash the system. This affects macOS Sequoia and macOS Tahoe, which are operating systems used on Apple computers. An exploit could lead to unexpected system shutdowns, potentially disrupting business operations and causing data loss for unsaved work.

Technical details

A buffer overflow vulnerability exists in macOS Sequoia (before 15.7.7) and macOS Tahoe (before 26.5). The flaw was addressed by implementing improved bounds checking. According to the advisory, a remote attacker can exploit this vulnerability to cause unexpected system termination (denial of service). While the specific component within the OS is not explicitly named in the brief description for CVE-2026-28848, the impact is categorized as a remote attack vector leading to system instability. Users are advised to update to macOS Sequoia 15.7.7 or macOS Tahoe 26.5.

Affected products

  • Apple macOS Sequoia versions before 15.7.7
  • Apple macOS Tahoe versions before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats