CVE-2026-28815: Apple Swift-Crypto

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1.

Affected products

  • Apple Swift-Crypto: from 4.0.0, before 4.3.1 (fixed in 4.3.1)

Published 2026-04-03. Last modified 2026-07-24.