Vulnerability Bulletins

CVE-2026-78236

   
Affected software APPLE
 
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-78236