CVE-2026-28909

MEDIUM

Apple macOS <0.12.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 11.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (2)
apple/container < 0.12.3
Apple/macOS 0.12.1 - 0.12.3
Published Apr 30, 2026
Tracked Since May 01, 2026