Executive brief
A vulnerability in macOS Sequoia could allow a malicious application to bypass security restrictions known as the sandbox. This sandbox is designed to isolate apps and protect sensitive user data; a breakout could lead to unauthorized access to files or system resources. Users should update to macOS Sequoia 15.1 to resolve this issue.
Technical details
A race condition (CWE-362) was identified in macOS Sequoia prior to version 15.1. The vulnerability exists due to improper synchronization during concurrent execution using shared resources. An attacker can exploit this by running a specially crafted application that leverages the race condition to escape the sandbox environment. Apple addressed the issue by implementing additional validation checks. While some metadata suggests a network attack vector, sandbox escapes typically involve local execution of a malicious app.
Affected products
- Apple macOS Sequoia before 15.1
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory: Apple released security notes for macOS Sequoia 15.1
- 2026-04-02: patched