Executive brief
A use-after-free memory management flaw in macOS could allow an app to cause unexpected system crashes or termination. This vulnerability affects multiple versions of Apple's operating system and could degrade system stability or be leveraged as part of a broader exploit chain targeting the kernel.
Technical details
This use-after-free vulnerability was addressed through improved memory management in the affected macOS versions. The issue allows an app running on the system to trigger unexpected termination by exploiting a memory object that is accessed after it has been freed. The vulnerability requires local code execution (an installed or running app) and does not require user interaction beyond normal system operation. While the reported CVSS score of 5.5 indicates medium severity, the use-after-free class of bug can potentially be chained with other vulnerabilities for privilege escalation or kernel code execution. Patches are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-09-14: disclosed: CVE-2026-28933 publicly disclosed
- 2026-07-27: patched: Fixes released in macOS Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6