CVE-2026-28815 identifies an out-of-bounds read vulnerability in Apple's swift-crypto library, specifically within the C decapsulation path for X-Wing HPKE encapsulated keys. A remote attacker can trigger this flaw by supplying a short, malformed key. Successful exploitation could lead to a denial-of-service condition via a crash or potentially memory disclosure, with a FAUCET Risk Score of 20.0/100 indicating a low-to-moderate risk. There is currently no evidence of active exploitation, no public exploit code available, and community discussion remains minimal. The issue is resolved in swift-crypto version 4.3.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.3.1CPE matchmatch criteria | cpe:2.3:a:apple:swift-crypto:*:*:*:*:*:swift:*:* | ||
>= 4.0.0, < 4.3.1CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.