CVE-2026-33448: Format string vulnerability in MacOS clients prior to 14.50
CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the log files potentially revealing secrets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33448?
CVE-2026-33448 is considered a high-severity vulnerability due to its potential for memory disclosure.
How do I fix CVE-2026-33448?
The recommended fix for CVE-2026-33448 is to upgrade the Secure Access client for macOS to version 14.50 or later.
What software versions are affected by CVE-2026-33448?
CVE-2026-33448 affects all versions of Secure Access client for macOS prior to 14.50.
What exploit can be used with CVE-2026-33448?
Attackers can exploit CVE-2026-33448 by using a modified server to force the macOS client to disclose memory contents.
Is CVE-2026-33448 a client-side or server-side vulnerability?
CVE-2026-33448 is primarily a client-side vulnerability affecting the logging subsystem of the Secure Access client.