Junglewise Threat Intelligence

CVE-2026-28915: Apple macOS CUPS privilege escalation in directory path parsing

CVE-2026-28915 · Severity: high · CVSS 7.8 · Published 2026-05-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A vulnerability in the CUPS printing component of macOS could allow a malicious application to gain full administrative (root) control over a computer. This could lead to complete system compromise, including the ability to access all user data, install persistent malware, or disable security features. Users should update their macOS software to the latest available version to mitigate this risk.

Technical details

A privilege escalation vulnerability exists in the CUPS (Common Unix Printing System) component of macOS due to improper parsing of directory paths. By exploiting this flaw, a local malicious application can bypass intended security restrictions to gain root-level privileges. The root cause is insufficient validation of path inputs, which Apple addressed by implementing improved path validation logic. The vulnerability affects multiple versions of macOS and requires the attacker to have the ability to execute code locally on the target system. Patches are available in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.

Affected products

  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.5

Timeline

  • 2026-05-11: disclosed: Initial publication by Apple and NVD
  • 2026-05-11: patched: Fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5

References

Related threats