CVE-2026-28815: Apple Swift-Crypto
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1.
Affected products
- Apple Swift-Crypto: from 4.0.0, before 4.3.1 (fixed in 4.3.1)
Published 2026-04-03. Last modified 2026-07-24.