CVE-2026-28815

A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apple:swift-crypto:*:*:*:*:*:swift:*:*

History

No history.

Information

Published : 2026-04-03 03:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-28815

Mitre link : CVE-2026-28815

CVE.ORG link : CVE-2026-28815


JSON object : View

Products Affected

apple

  • swift-crypto
CWE
CWE-125

Out-of-bounds Read