CVE-2026-28930: Input Validation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.
Other sources
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
Accelerate. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Accessibility. This issue was addressed with improved data protection.
— Apple
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
AirDrop. A reachable assertion was addressed with improved input validation.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.8
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28991
- CVE-2026-28988
- CVE-2026-43667
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-1837
- CVE-2026-28956
- CVE-2026-39869
- CVE-2026-28849
- CVE-2026-28922
- CVE-2026-28936
- CVE-2026-28918
- CVE-2026-28915
- CVE-2025-14017
- CVE-2025-14819
- CVE-2026-43659
- CVE-2026-28923
- CVE-2026-28925
- CVE-2026-43661
- CVE-2026-28977
- CVE-2026-28990
- CVE-2026-28978
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-39877
- CVE-2026-43655
- CVE-2026-43654
- CVE-2026-28908
- CVE-2026-28954
- CVE-2026-28897
- CVE-2026-28952
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-28900
- CVE-2026-28929
- CVE-2026-43653
- CVE-2026-28985
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28941
- CVE-2026-28940
- CVE-2026-28961
- CVE-2026-28906
- CVE-2026-43656
- CVE-2026-43652
- CVE-2026-39870
- CVE-2026-28846
- CVE-2026-28993
- CVE-2026-28848
- CVE-2026-28930
- CVE-2026-28974
- CVE-2026-28996
- CVE-2026-28919
- CVE-2026-28924
- CVE-2026-39871
- CVE-2026-28976
- CVE-2026-43660
- CVE-2026-28907
- CVE-2026-28962
- CVE-2026-43658
- CVE-2026-28984
- CVE-2026-28905
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28955
- CVE-2026-28903
- CVE-2026-28953
- CVE-2026-28902
- CVE-2026-28901
- CVE-2026-28913
- CVE-2026-28883
- CVE-2026-28958
- CVE-2026-28917
- CVE-2026-28947
- CVE-2026-28946
- CVE-2026-28942
- CVE-2026-28971
- CVE-2026-43670
- CVE-2026-28944
- CVE-2026-28819
- CVE-2026-28994
- CVE-2026-28914
- CVE-2026-28920
- CVE-2026-86882
- CVE-2026-43664
- CVE-2026-86910
- CVE-2026-84523
- CVE-2026-84587
- CVE-2026-20683
- CVE-2026-65408
- CVE-2026-65407
- CVE-2026-84519
- CVE-2026-65381
- CVE-2026-43763
- CVE-2026-84525
- CVE-2026-65342
- CVE-2026-65339
- CVE-2026-84583
- CVE-2026-84568
- CVE-2026-84570
- CVE-2026-84535
- CVE-2026-84616
- CVE-2026-84607
- CVE-2026-65406
- CVE-2026-65414
- CVE-2026-84567
- CVE-2026-65399
- CVE-2026-86891
- CVE-2026-43683
- CVE-2026-43789
- CVE-2026-65344
- CVE-2026-86876
- CVE-2026-43702
- CVE-2026-84624
- CVE-2026-43737
- CVE-2026-84574
- CVE-2026-84559
- CVE-2026-43786
- CVE-2026-65412
- CVE-2026-84575
- CVE-2026-84511
- CVE-2026-84563
- CVE-2026-84540
- CVE-2026-84554
- CVE-2026-43692
- CVE-2026-64790
- CVE-2026-43691
- CVE-2026-84516
- CVE-2026-84541
- CVE-2026-84612
- CVE-2026-84505
- CVE-2026-84565
- CVE-2026-84552
- CVE-2026-84550
- CVE-2026-65362
- CVE-2026-84512
- CVE-2026-84510
- CVE-2026-43785
- CVE-2026-84534
- CVE-2026-84524
- CVE-2026-65409
- CVE-2026-84618
- CVE-2026-84492
- CVE-2022-3437
- CVE-2026-28934
- CVE-2026-84581
- CVE-2026-64756
- CVE-2026-84564
- CVE-2026-64758
- CVE-2026-65346
- CVE-2026-65395
- CVE-2026-64736
- CVE-2026-84566
- CVE-2026-28968
- CVE-2026-84619
- CVE-2026-84549
- CVE-2026-43790
- CVE-2026-84622
- CVE-2026-65377
- CVE-2026-65369
- CVE-2026-84544
- CVE-2026-86917
- CVE-2026-43684
- CVE-2026-43686
- CVE-2026-84538
- CVE-2026-65364
- CVE-2026-65405
- CVE-2026-84630
- CVE-2026-65360
- CVE-2026-65358
- CVE-2026-84602
- CVE-2026-65349
- CVE-2026-65330
- CVE-2026-28935
- CVE-2026-65402
- CVE-2026-84521
- CVE-2026-84507
- CVE-2026-84517
- CVE-2026-84561
- CVE-2026-65359
- CVE-2026-65371
- CVE-2026-84514
- CVE-2026-84556
- CVE-2026-65382
- CVE-2026-84573
- CVE-2026-43787
- CVE-2026-43741
- CVE-2026-84497
- CVE-2026-84626
- CVE-2026-43695
- CVE-2026-64712
- CVE-2026-84580
- CVE-2026-84578
- CVE-2026-84576
- CVE-2026-84548
- CVE-2026-84532
- CVE-2026-28966
- CVE-2026-65403
- CVE-2026-84555
- CVE-2026-84632
- CVE-2026-84487
- CVE-2026-65413
- CVE-2026-84620
- CVE-2026-84546
- CVE-2026-84611
- CVE-2026-43697
- CVE-2026-84526
- CVE-2026-86889
- CVE-2026-86881
- CVE-2026-43719
- CVE-2026-43690
- CVE-2026-65376
- CVE-2026-84543
- CVE-2026-84536
- CVE-2026-84537
- CVE-2026-65365
- CVE-2026-84515
- CVE-2026-84509
- CVE-2026-84553
- CVE-2026-84609
- CVE-2026-65361
- CVE-2026-65378
- CVE-2026-84621
- CVE-2026-65345
- CVE-2026-65348
- CVE-2026-43791
- CVE-2026-84513
- CVE-2026-84527
- CVE-2026-84572
- CVE-2026-84506
- CVE-2026-43677
- CVE-2026-65375
- CVE-2026-65374
- CVE-2026-28899
- CVE-2026-84617
Frequently Asked Questions
What is the severity of CVE-2026-28930?
CVE-2026-28930 is considered a high-severity vulnerability due to its potential to allow unauthorized access to protected user data.
How do I fix CVE-2026-28930?
To fix CVE-2026-28930, update your macOS Tahoe to version 26.5 or later, as it includes the necessary patches.
What versions of macOS Tahoe are affected by CVE-2026-28930?
CVE-2026-28930 affects macOS Tahoe versions prior to 26.5.
What kind of issue is described in CVE-2026-28930?
CVE-2026-28930 describes a permissions issue that could allow an application to access protected user data.
What improvements were made to address CVE-2026-28930?
CVE-2026-28930 was addressed with additional restrictions and improved bounds checking to prevent out-of-bounds reads.