Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HSummary
CVE-2026-28822 is a medium-severity Type Confusion (CWE-843) vulnerability in Apple Macos. Its CVSS base score is 6.2 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Application or System Exploitation (T1499.004); ranked at the 10th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-16 (Memory Protection) and SI-2 (Flaw Remediation) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-15087
Vulnerability Data
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker may be able…
more
to cause unexpected app termination.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Type confusion (CWE-843) directly enables application crash/termination as described, mapping to exploitation-based DoS.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces memory protections that prevent type confusion (CWE-843) from causing invalid memory access and app termination.
Requires timely application of vendor patches that address the type confusion flaw via improved memory handling in affected Apple OS versions.
Mandates developer testing and evaluation (e.g., fuzzing, static analysis) to discover type confusion issues before release.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent type-confusion flaws via safe typing, static analysis, and code review while the control itself addresses many additional weaknesses.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can detect type-confusion vulnerabilities through fuzzing and static analysis.
Secure SDLC mandates type-safe design and review that can catch type-confusion flaws.
Application security requirements can specify strong typing and interface contracts that reduce type confusion.
Secure architecture principles promote type-safe languages and memory-safety mechanisms that mitigate type confusion.
Secure coding standards directly forbid unsafe type casts and require static-analysis checks for type confusion.