CVE-2026-28981

Published Jul 27, 2026

Last updated a day ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-28981 describes a buffer overflow vulnerability that was resolved through enhanced bounds checking. This flaw could enable arbitrary code execution if a user processes a specially crafted image. Apple addressed this issue in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.

Description
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.
Source
product-security@apple.com
NVD status
Analyzed
Products
macos

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-120

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

7

Configurations