Executive brief
Apple macOS uses a sandbox mechanism to isolate applications and prevent them from accessing sensitive system resources or user files without permission. A logic issue in the File Bookmark component allows a malicious app to break out of this sandbox restriction. An attacker could distribute a trojanized app that escapes sandbox confinement, potentially accessing protected user data and system resources.
Technical details
The vulnerability is a logic issue in Apple's File Bookmark functionality that fails to properly validate and enforce sandbox boundary checks. The flaw allows a sandboxed application to bypass sandbox restrictions through crafted file bookmark operations. An attacker would need to convince a user to install and run a malicious application on the target macOS system. Successful exploitation grants the attacker's app access to protected files and resources outside the sandbox, effectively breaking the isolation that would normally restrict the app's capabilities. Apple addressed this issue with improved validation logic in File Bookmark handling across multiple macOS versions.
Affected products
- Apple macOS Sequoia 15.7.4
- Apple macOS Sonoma 14.8.4
- Apple macOS Tahoe 26.2
Timeline
- 2025-12-12: patched: Fixed in macOS Tahoe 26.2
- 2026-02-11: patched: Fixed in macOS Sequoia 15.7.4 and macOS Sonoma 14.8.4
- 2025-12-17: disclosed