---
id: CVE-2026-28961
title: This issue was addressed with improved checks
summary: >-
  This issue was addressed with improved checks. This issue is fixed in macOS
  Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with
  physical access to a locked device may be able to view sensitive user
  information.
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: apple
product: macos
affected:
  - 'macos >= 26.0, < 26.5'
patched:
  - macos 26.5
published: '2026-05-11'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-28961'
references:
  - url: 'https://support.apple.com/en-us/127115'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/128071'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/128072'
    label: product-security@apple.com
tags:
  - nvd
epss: 0.00203
epssPercentile: 0.09117
ingestedAt: '2026-07-27T21:24:36.815Z'
---

## Overview

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.

## Affected

- `macos >= 26.0, < 26.5`

## Remediation

Upgrade past the affected range:

- `macos 26.5`
