---
id: CVE-2026-28914
title: A logic issue was addressed with improved file handling
summary: >-
  A logic issue was addressed with improved file handling. This issue is fixed
  in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously
  crafted ZIP archive may bypass Gatekeeper checks.
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-358
  - CWE-693
vendor: apple
product: macos
affected:
  - 'macos >= 26.0, < 26.5'
patched:
  - macos 26.5
published: '2026-05-11'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-28914'
references:
  - url: 'https://support.apple.com/en-us/127115'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/128071'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/128072'
    label: product-security@apple.com
tags:
  - nvd
epss: 0.00172
epssPercentile: 0.05868
ingestedAt: '2026-07-27T21:24:36.736Z'
---

## Overview

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

## Affected

- `macos >= 26.0, < 26.5`

## Remediation

Upgrade past the affected range:

- `macos 26.5`
