Executive brief
A security vulnerability in the Assets component of Apple operating systems could allow a malicious application to bypass its security boundaries. Normally, apps are restricted to a 'sandbox' to prevent them from accessing data or systems they shouldn't; this flaw allows an app to break out of that restricted area. This could lead to unauthorized access to sensitive user information or system functions. Apple has released software updates to address this issue by improving how app permissions are handled.
Technical details
A sandbox escape vulnerability exists in the Assets component of multiple Apple operating systems. The flaw is rooted in improper entitlement management, which can be exploited by a malicious application to bypass sandbox restrictions. An attacker could leverage this to gain unauthorized access to system resources or user data outside of the application's intended scope. The issue was addressed by implementing improved entitlement checks and additional restrictions. The vulnerability affects iOS, iPadOS, macOS (Sonoma, Sequoia, Tahoe), tvOS, and visionOS.
Affected products
- Apple iOS < 18.7.2, < 26.1
- Apple iPadOS < 18.7.2, < 26.1
- Apple macOS Sequoia < 15.7.2
- Apple macOS Sonoma < 14.8.2
- Apple macOS Tahoe < 26.1
- Apple tvOS < 26.1
- Apple visionOS < 26.1
Timeline
- 2025-11-03: disclosed: Initial disclosure by Apple
- 2025-11-03: patched: Fixed in iOS 26.1, iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1
- 2025-11-04: advisory: NVD publication date
- 2026-06-10: other: iOS 18.7.2 and iPadOS 18.7.2 added to affected versions list