Executive brief
A vulnerability in macOS Sequoia could allow a malicious application to bypass security restrictions known as the sandbox. The sandbox is designed to isolate apps and prevent them from accessing sensitive user data or system resources they aren't authorized to use. If exploited, a rogue app could gain unauthorized access to private information or perform actions outside of its intended boundaries.
Technical details
A sandbox escape vulnerability exists in macOS Sequoia prior to version 15.6 due to improper link resolution (CWE-59) when handling symbolic links. A local attacker can exploit this by using a malicious application to bypass sandbox restrictions, potentially gaining unauthorized access to sensitive data or system resources. The issue was addressed by Apple through improved handling of symlinks. The vulnerability is tracked as CVE-2025-43257 and has a CVSS v3.1 base score of 8.7, reflecting its high impact on confidentiality and integrity despite requiring local access.
Affected products
- Apple macOS Sequoia before 15.6
Timeline
- 2026-04-02: advisory: Initial disclosure by Apple and NVD publication
- 2026-04-02: patched: Fixed in macOS Sequoia 15.6