Metrics
Affected Vendors & Products
No advisories yet.
Solution
Users and administrators of affected product versions are advised to update to the latest version promptly.
Workaround
No workaround given by the vendor.
Wed, 26 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 CWE-287 CWE-327 |
|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 26 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process. | |
| Title | Insecure PIN derivation mechanism in Admin By Request (ABR) | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CSA
Published:
Updated: 2026-08-26T14:02:09.555Z
Reserved: 2026-08-24T03:00:17.827Z
Link: CVE-2026-78236
Updated: 2026-08-26T14:02:05.329Z
Status : Received
Published: 2026-08-26T08:16:46.600
Modified: 2026-08-26T14:17:15.887
Link: CVE-2026-78236
No data.
OpenCVE Enrichment
Updated: 2026-08-26T08:30:03Z