Description
This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A local attacker may gain access to user's Keychain items.
Published: 2026-03-25
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Keychain Access
Action: Patch
AI Analysis

Impact

A local attacker can bypass permissions checking to access a user's Keychain items, exposing stored passwords, certificates, and other sensitive credentials. The weakness is a failure to properly enforce access control (CWE-863). The compromised data can lead to credential theft, further attacks, or unauthorized system access, affecting the confidentiality and integrity of user data.

Affected Systems

Apple iOS, iPadOS, macOS, visionOS, and watchOS. Versions affected include iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, and watchOS 26.4.

Risk and Exploitability

The CVSS score of 3.3 indicates low severity, and the EPSS score is less than 1 percent, suggesting a very low probability of exploitation. The vulnerability is not listed in the KEV catalog. Because the attack requires local device access, it is most relevant to situations where an attacker can physically or remotely interact with the device while the user is logged in or has provided authentication. No public exploit is known, and the simplified fix is to update to the patched OS releases.

Generated by OpenCVE AI on March 25, 2026 at 19:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest version of the affected operating system, such as iOS 18.7.7, iPadOS 18.7.7, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, or watchOS 26.4.
  • If an upgrade is not immediately possible, monitor the device for unexpected Keychain read operations and lock the device when not in use.
  • Ensure that all users are aware of the importance of securing their device with a strong lock and not sharing access with untrusted parties.

Generated by OpenCVE AI on March 25, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Title Local Keychain Access Exploit in Apple Operating Systems

Wed, 25 Mar 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 25 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos

Wed, 25 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A local attacker may gain access to user's Keychain items.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:27:26.085Z

Reserved: 2026-03-03T16:36:03.973Z

Link: CVE-2026-28864

cve-icon Vulnrichment

Updated: 2026-03-25T14:18:09.296Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T01:17:10.453

Modified: 2026-03-25T18:29:21.090

Link: CVE-2026-28864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T21:16:02Z

Weaknesses