Junglewise Threat Intelligence

CVE-2024-44250: Apple macOS Sequoia privilege escalation in sandbox

CVE-2024-44250 · Severity: high · CVSS 8.2 · Published 2026-04-02

Technologies: Apple macOS. Vendors: Apple.

Executive brief

macOS Sequoia is the operating system used on Apple Mac computers. A security flaw in the system's permission management could allow a malicious application to bypass its security sandbox. If exploited, the app could gain elevated privileges or execute unauthorized code, potentially compromising sensitive user data or system integrity.

Technical details

A permissions issue (CWE-269) was identified in macOS Sequoia prior to version 15.1. The vulnerability stems from improper privilege management, which could allow a local application to escape its sandbox environment. An attacker with high privileges could leverage this flaw to execute arbitrary code with further elevated permissions or across security boundaries (Scope: Changed). Apple addressed this issue by implementing additional restrictions in macOS Sequoia 15.1.

Affected products

  • Apple macOS Sequoia up to (excluding) 15.1

Timeline

  • 2024-10-24: patched: Fixed in macOS Sequoia 15.1
  • 2026-04-02: disclosed: NVD publication date

References

Related threats