Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple ipados
Apple iphone Os |
|
| CPEs | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple ipados
Apple iphone Os |
Tue, 12 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Gatekeeper Disk Image Quarantine Bypass Allowing Execution of Malicious Binaries |
Tue, 12 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Gatekeeper Quarantine Bypass via Malicious Disk Images | |
| Weaknesses | CWE-285 CWE-640 |
Tue, 12 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| Metrics |
cvssV3_1
|
Mon, 11 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Gatekeeper Quarantine Bypass via Malicious Disk Images | |
| Weaknesses | CWE-285 CWE-640 |
Mon, 11 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios And Ipados Apple macos |
|
| Vendors & Products |
Apple
Apple ios And Ipados Apple macos |
Mon, 11 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted disk image may bypass Gatekeeper checks. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-05-12T13:05:06.904Z
Reserved: 2026-03-03T16:36:03.990Z
Link: CVE-2026-28954
Updated: 2026-05-12T13:04:55.757Z
Status : Analyzed
Published: 2026-05-11T21:18:56.467
Modified: 2026-05-12T17:21:41.890
Link: CVE-2026-28954
No data.
OpenCVE Enrichment
Updated: 2026-05-12T16:30:19Z