Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9m44-rr2w-ppp7 | Swift Crypto: X-Wing HPKE Decapsulation Accepts Malformed Ciphertext Length |
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Read in HPKE Decapsulation Leading to Potential Memory Disclosure |
Mon, 13 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple swift-crypto
|
|
| CPEs | cpe:2.3:a:apple:swift-crypto:*:*:*:*:*:swift:*:* | |
| Vendors & Products |
Apple swift-crypto
|
Tue, 07 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Read in HPKE Decapsulation Leading to Potential Memory Disclosure |
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out‑of‑Bounds Read in Swift Crypto HPKE Decapsulation | |
| Weaknesses | CWE-200 |
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out‑of‑Bounds Read in Swift Crypto HPKE Decapsulation | |
| First Time appeared |
Apple
Apple macos |
|
| Weaknesses | CWE-125 CWE-200 |
|
| Vendors & Products |
Apple
Apple macos |
Fri, 03 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-04-03T13:39:46.737Z
Reserved: 2026-03-03T16:36:03.967Z
Link: CVE-2026-28815
Updated: 2026-04-03T13:39:13.993Z
Status : Analyzed
Published: 2026-04-03T03:16:18.093
Modified: 2026-04-13T17:50:58.550
Link: CVE-2026-28815
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:41:52Z
Github GHSA