CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ⬡ Vulnerabilities & CVEs Apr 03, 2026

CVE-2026-28815 | Apple macOS up to 4.3.0 out-of-bounds (GHSA-9m44-rr2w-ppp7)

VulDB Archived Apr 03, 2026 ✓ Full text saved

A vulnerability classified as critical was found in Apple macOS up to 4.3.0 . The impacted element is an unknown function. Executing a manipulation can lead to out-of-bounds read. The identification of this vulnerability is CVE-2026-28815 . The attack may be launched remotely. There is no exploit available. Upgrading the affected component is advised.

Full text archived locally
✦ AI Summary · Claude Sonnet


    VDB-355055 · CVE-2026-28815 · GHSA-9M44-RR2W-PPP7 APPLE MACOS UP TO 4.3.0 OUT-OF-BOUNDS HISTORYDIFFRELATEJSONXMLCTI CVSS Meta Temp Score Current Exploit Price (≈) CTI Interest Score 7.0 $0-$5k 0.66+ Summaryinfo A vulnerability, which was classified as critical, has been found in Apple macOS up to 4.3.0. This affects an unknown function. The manipulation leads to out-of-bounds. This vulnerability is referenced as CVE-2026-28815. Remote exploitation of the attack is possible. No exploit is available. It is advisable to upgrade the affected component. Detailsinfo A vulnerability was found in Apple macOS up to 4.3.0 and classified as critical. This issue affects an unknown functionality. The manipulation with an unknown input leads to a out-of-bounds vulnerability. Using CWE to declare the problem leads to CWE-125. The product reads data past the end, or before the beginning, of the intended buffer. Impacted is confidentiality, integrity, and availability. The summary by CVE is: A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1. It is possible to read the advisory at github.com. The identification of this vulnerability is CVE-2026-28815 since 03/03/2026. The exploitation is known to be easy. The attack may be initiated remotely. No form of authentication is needed for a successful exploitation. The technical details are unknown and an exploit is not publicly available. The pricing for an exploit might be around USD $0-$5k at the moment (estimation calculated on 04/03/2026). Upgrading to version 4.3.1 eliminates this vulnerability. Productinfo Type Operating System Vendor Apple Name macOS Version 4.0 4.1 4.2 4.3.0 License commercial Website Vendor: https://www.apple.com/ CPE 2.3info 🔒 🔒 🔒 CPE 2.2info 🔒 🔒 🔒 CVSSv4info VulDB Vector: 🔒 VulDB Reliability: 🔍 CVSSv3info VulDB Meta Base Score: 7.3 VulDB Meta Temp Score: 7.0 VulDB Base Score: 7.3 VulDB Temp Score: 7.0 VulDB Vector: 🔒 VulDB Reliability: 🔍 CVSSv2info Vector Complexity Authentication Confidentiality Integrity Availability Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock Unlock VulDB Base Score: 🔒 VulDB Temp Score: 🔒 VulDB Reliability: 🔍 Exploitinginfo Class: Out-of-bounds CWE: CWE-125 / CWE-119 CAPEC: 🔒 ATT&CK: 🔒 Physical: No Local: No Remote: Yes Availability: 🔒 Status: Not defined Price Prediction: 🔍 Current Price Estimation: 🔒 0-Day Unlock Unlock Unlock Unlock Today Unlock Unlock Unlock Unlock Threat Intelligenceinfo Interest: 🔍 Active Actors: 🔍 Active APT Groups: 🔍 Countermeasuresinfo Recommended: Upgrade Status: 🔍 0-Day Time: 🔒 Upgrade: macOS 4.3.1 Timelineinfo 03/03/2026 CVE reserved 04/03/2026 +30 days Advisory disclosed 04/03/2026 +0 days VulDB entry created 04/03/2026 +0 days VulDB entry last update Sourcesinfo Vendor: apple.com Advisory: GHSA-9m44-rr2w-ppp7 Status: Confirmed CVE: CVE-2026-28815 (🔒) GCVE (CVE): GCVE-0-2026-28815 GCVE (VulDB): GCVE-100-355055 scip Labs: https://www.scip.ch/en/?labs.20180712 Entryinfo Created: 04/03/2026 07:45 Changes: 04/03/2026 07:45 (57) Complete: 🔍 Cache ID: 99:923:101 Discussion No comments yet. Languages: en. Please log in to comment. ◂ PreviousOverviewNext ▸
    💬 Team Notes
    Article Info
    Source
    VulDB
    Category
    ⬡ Vulnerabilities & CVEs
    Published
    Apr 03, 2026
    Archived
    Apr 03, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗