Executive brief
A security vulnerability in macOS Sequoia could allow a malicious application to bypass built-in security restrictions known as the sandbox. By breaking out of this sandbox, an app could perform unauthorized actions on the system that it should not have permission to do. This could lead to the compromise of user data or unauthorized changes to system settings.
Technical details
A sandbox escape vulnerability exists in macOS Sequoia prior to version 15.4. The flaw is characterized by insufficient checks that allow a malicious application to bypass sandbox restrictions and perform unauthorized actions. While the specific root cause (e.g., path handling or logic error) is not detailed in the brief advisory for this specific CVE, it is categorized as a sandbox breakout. An attacker would need to entice a user to run a malicious application on the local system to exploit this. Apple addressed the issue by implementing improved validation checks in macOS Sequoia 15.4.
Affected products
- Apple macOS Sequoia Before 15.4
Timeline
- 2025-03-31: patched: Fixed in macOS Sequoia 15.4
- 2026-06-11: disclosed: NVD publication date