Ghostwire

CVE-2026-33448: CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to...

MEDIUM CVSS 5.5

Published: April 30, 2026 | Last Modified: April 30, 2026

Description

CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the log files potentially revealing secrets.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References