CVE-2026-65388: Apple Containerization
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.
Affected products
- Apple Containerization: before 0.41.0 (fixed in 0.41.0)
Published 2026-09-16. Last modified 2026-09-18.