Description
A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
Published: 2026-03-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure
Action: Patch
AI Analysis

Impact

A privacy issue within macOS allows an application to access sensitive user information that was previously protected by moving data into a more secure location. The flaw is a form of improper access control that could lead to confidential data being read by an unauthorized app. As a result, user privacy is directly impacted, with the potential for personal data to be disclosed to a malicious or unintended application.

Affected Systems

Apple macOS is the affected platform. The vulnerability existed in versions prior to macOS Tahoe 26.4, which includes the 26.4 update that fixed the issue. No other vendors or product versions were specified.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, further indicating limited real-world exploitation. Attackers would need to run or install an application that can leverage the broken access control to read protected data. The exploit requires no special user interaction beyond normal application use, but it is limited to platforms with the affected macOS versions. While the threat is moderate, remediation is prudent.

Generated by OpenCVE AI on March 26, 2026 at 14:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install macOS Tahoe 26.4 or later, ensuring that the system update has been applied.

Generated by OpenCVE AI on March 26, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 27 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
Title Privacy Exposure via Sensitive Data Access in macOS

Thu, 26 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Title Potential Access to Sensitive User Data via Privacy Issue in macOS
Weaknesses CWE-200

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Title Potential Access to Sensitive User Data via Privacy Issue in macOS
Weaknesses CWE-200

Wed, 25 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 25 Mar 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Wed, 25 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:22:27.190Z

Reserved: 2026-03-03T16:36:03.975Z

Link: CVE-2026-28881

cve-icon Vulnrichment

Updated: 2026-03-25T19:50:11.386Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T01:17:11.957

Modified: 2026-03-25T20:30:46.320

Link: CVE-2026-28881

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-27T09:50:31Z

Weaknesses