Executive brief
macOS Sequoia is the operating system used on Apple Mac computers. A security flaw in the system's permission management could allow a malicious application to bypass its security sandbox. If exploited, the app could gain elevated privileges or execute unauthorized code, potentially compromising sensitive user data or system integrity.
Technical details
A permissions issue (CWE-269) was identified in macOS Sequoia prior to version 15.1. The vulnerability stems from improper privilege management, which could allow a local application to escape its sandbox environment. An attacker with high privileges could leverage this flaw to execute arbitrary code with further elevated permissions or across security boundaries (Scope: Changed). Apple addressed this issue by implementing additional restrictions in macOS Sequoia 15.1.
Affected products
- Apple macOS Sequoia up to (excluding) 15.1
Timeline
- 2024-10-24: patched: Fixed in macOS Sequoia 15.1
- 2026-04-02: disclosed: NVD publication date