A path handling issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.4. An app with root privileges may be able to delete protected system files.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.apple.com/en-us/126794 |
|
History
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Handling Bug Enabling Deletion of Protected System Files in macOS |
Wed, 25 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
Wed, 25 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos |
|
| Vendors & Products |
Apple
Apple macos |
Wed, 25 Mar 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path handling issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.4. An app with root privileges may be able to delete protected system files. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-03-25T19:45:11.725Z
Reserved: 2026-03-03T16:36:03.968Z
Link: CVE-2026-28823
Updated: 2026-03-25T19:45:07.933Z
Status : Analyzed
Published: 2026-03-25T01:17:07.493
Modified: 2026-03-25T20:29:05.337
Link: CVE-2026-28823
No data.
OpenCVE Enrichment
Updated: 2026-03-25T21:48:15Z