Junglewise Threat Intelligence

CVE-2026-28849: Apple macOS Gatekeeper bypass via crafted ZIP archive

CVE-2026-28849 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Sequoia. Vendors: Apple.

Executive brief

A security bypass vulnerability exists in macOS that could allow untrusted software to run on a user's computer. Gatekeeper, the security feature designed to ensure only trusted apps run, can be bypassed using a specially crafted ZIP archive. If exploited, this could allow malicious software to execute without the usual security warnings or blocks.

Technical details

A vulnerability in macOS Gatekeeper allows for a security bypass when handling ZIP archives. By crafting a malicious ZIP file, an attacker can circumvent the 'quarantine' attribute checks that Gatekeeper relies on to verify the integrity and origin of downloaded applications. This could lead to the execution of unsigned or malicious code that would otherwise be blocked by the operating system. The root cause was insufficient validation during the archive expansion or inspection process, which Apple addressed by implementing improved checks. Exploitation typically requires a user to download and open a malicious archive.

Affected products

  • Apple macOS Sequoia before 15.7.8
  • Apple macOS Sonoma before 14.8.8

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats