CVE-2026-78236

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-26 08:16

Updated : 2026-09-03 16:59


NVD link : CVE-2026-78236

Mitre link : CVE-2026-78236

CVE.ORG link : CVE-2026-78236


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-285

Improper Authorization

CWE-287

Improper Authentication

CWE-327

Use of a Broken or Risky Cryptographic Algorithm