Junglewise Threat Intelligence

CVE-2025-46281: Apple macOS File Bookmark sandbox escape

CVE-2025-46281 · Severity: high · CVSS 8.8 · Published 2025-12-17

Technologies: Apple macOS. Vendors: Apple.

Executive brief

Apple macOS uses a sandbox mechanism to isolate applications and prevent them from accessing sensitive system resources or user files without permission. A logic issue in the File Bookmark component allows a malicious app to break out of this sandbox restriction. An attacker could distribute a trojanized app that escapes sandbox confinement, potentially accessing protected user data and system resources.

Technical details

The vulnerability is a logic issue in Apple's File Bookmark functionality that fails to properly validate and enforce sandbox boundary checks. The flaw allows a sandboxed application to bypass sandbox restrictions through crafted file bookmark operations. An attacker would need to convince a user to install and run a malicious application on the target macOS system. Successful exploitation grants the attacker's app access to protected files and resources outside the sandbox, effectively breaking the isolation that would normally restrict the app's capabilities. Apple addressed this issue with improved validation logic in File Bookmark handling across multiple macOS versions.

Affected products

  • Apple macOS Sequoia 15.7.4
  • Apple macOS Sonoma 14.8.4
  • Apple macOS Tahoe 26.2

Timeline

  • 2025-12-12: patched: Fixed in macOS Tahoe 26.2
  • 2026-02-11: patched: Fixed in macOS Sequoia 15.7.4 and macOS Sonoma 14.8.4
  • 2025-12-17: disclosed

References

Related threats