Junglewise Threat Intelligence

CVE-2025-43524: Apple macOS sandbox escape in Icons

CVE-2025-43524 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Apple macOS Tahoe. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to bypass built-in security protections known as the sandbox. The sandbox is designed to isolate apps and prevent them from accessing data or system resources they aren't authorized to use. If exploited, a rogue app could break out of these restrictions to access sensitive user information or interfere with other parts of the operating system.

Technical details

An access control vulnerability (CWE-284) exists in the Icons component of macOS. The flaw is caused by insufficient sandbox restrictions, which can be leveraged by a local application to perform a sandbox escape. By breaking out of the sandbox, an attacker-controlled process can gain unauthorized access to protected files or system resources outside of its intended container. Apple addressed this logic issue by implementing additional sandbox restrictions and improved validation. The vulnerability affects macOS Sequoia, Sonoma, and Tahoe, and is fixed in versions 15.7.7, 14.8.7, and 26.2 respectively.

Affected products

  • Apple macOS Sequoia before 15.7.7
  • Apple macOS Sonoma before 14.8.7
  • Apple macOS Tahoe before 26.2

Timeline

  • 2025-12-12: patched: Initial patch release for macOS Tahoe 26.2
  • 2026-05-11: advisory: Entry added to Apple security advisory
  • 2026-05-12: disclosed: CVE published to NVD

References

Related threats