Junglewise Threat Intelligence

CVE-2026-28926: Apple macOS privilege escalation via race condition

CVE-2026-28926 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Apple macOS Sonoma. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to gain higher-level system permissions than it should normally have. This issue affects computers running macOS Sonoma and Sequoia. If exploited, an attacker could potentially bypass security restrictions to access sensitive data or modify system settings.

Technical details

A race condition exists in macOS Sequoia and Sonoma due to improper state handling. A local attacker can exploit this vulnerability by running a specially crafted application to gain elevated privileges on the target system. The vulnerability was mitigated by improving state management within the affected component. Patches are available in macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8.

Affected products

  • Apple macOS Sequoia before 15.7.8
  • Apple macOS Sonoma before 14.8.8

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats