Brave CEO Brendan Eich says the company might reconsider putting its privacy browser on the Mac App Store following warnings about security vulnerabilities in macOS web downloads.

The discussion started when security researchers at Mysk posted on X about a macOS Archive Utility bug tracked as CVE-2026-28910.

mysk-mac-app-store-benefits-post

The vulnerability allowed attackers to bypass Apple’s App Sandbox data containers and transparency protections.

Mysk pointed out that apps downloaded directly from developer websites are susceptible to executable hijacking. The researchers specifically named Brave and Mullvad as vulnerable targets, praising DuckDuckGo for being the only private browser distributed through the Mac App Store.

Eich responded in the thread after someone had tagged him. He argued that Apple needs to fix macOS itself rather than forcing developers into its ecosystem.

He also acknowledged the situation might force a strategy shift, stating that putting Brave in the Mac App Store “has hair on it” but is something the team can look at again.

brave-ceo-apple-app-store-comment-for-mac

The reluctance is common among browser developers. One user in the thread pointed out the main drawback of the App Store is Apple’s strict review process.

If a browser needs an urgent security patch for a zero-day exploit, developers have to wait for Apple to approve the update before users can download it. Direct web downloads bypass this bottleneck.

That said, the specific Archive Utility bug that kick-started the debate is no longer active. Apple patched it in the macOS 26.4 update.

CVE-2026-28910-patched-apple-macos-26-4

An independent researcher replying to Mysk also noted that the exploit was difficult to execute in the real world. It required a victim to run an attacker’s shell script and manually drag and drop files.

Mysk dismissed that defense. The firm claimed other unpatched local vulnerabilities currently exist in macOS that can hijack executables without requiring any user interaction.

mysk-discussion-apple-app-store-apps-security

That said, it’s anyone’s guess as to when Brave might appear on the App Store, if at all.

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Dwayne Cubbins
2715 Posts

I cover fast-moving stories across apps, online platforms, and everyday tech — phones, wearables, consoles, and whatever else people are fighting with this week. Bugs, rollouts, scams, policy enforcement, and the occasional internet-culture rabbit hole are all fair game. My goal is simple — make confusing tech news readable. When I'm not working, I'm working out or chilling with my dog. Got a tip? You can find me on X @dcubbins.

Next article View Article

If you read articles in Firefox Reader View on iPhone, install the latest update now

Mozilla pushed Firefox for iOS 151.2 on June 1 to fix two security vulnerabilities in Reader View, both rated high severity. Reader View is the stripped-down reading mode...
Jun 02, 2026 1 Min Read