Junglewise Threat Intelligence

CVE-2024-40849: Apple macOS race condition in sandbox isolation

CVE-2024-40849 · Severity: high · CVSS 7.5 · Published 2026-04-02

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A vulnerability in macOS Sequoia could allow a malicious application to bypass security restrictions known as the sandbox. This sandbox is designed to isolate apps and protect sensitive user data; a breakout could lead to unauthorized access to files or system resources. Users should update to macOS Sequoia 15.1 to resolve this issue.

Technical details

A race condition (CWE-362) was identified in macOS Sequoia prior to version 15.1. The vulnerability exists due to improper synchronization during concurrent execution using shared resources. An attacker can exploit this by running a specially crafted application that leverages the race condition to escape the sandbox environment. Apple addressed the issue by implementing additional validation checks. While some metadata suggests a network attack vector, sandbox escapes typically involve local execution of a malicious app.

Affected products

  • Apple macOS Sequoia before 15.1

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory: Apple released security notes for macOS Sequoia 15.1
  • 2026-04-02: patched

References

Related threats