Executive brief
A security vulnerability in macOS could allow a malicious application to bypass sandbox restrictions. The sandbox is a security layer designed to prevent apps from accessing data or system resources they aren't authorized to use. If exploited, a malicious app could perform actions outside of its intended restricted environment, potentially compromising system integrity.
Technical details
A logic issue existed in the CoreServices component of macOS, specifically related to sandbox permissions. An attacker could exploit this by using a malicious application to bypass sandbox restrictions, allowing the app to interact with system resources or data outside of its isolated environment. The vulnerability was addressed by implementing additional sandbox restrictions to enforce proper isolation. The issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4.
Affected products
- Apple macOS Sequoia before 15.7.5
- Apple macOS Sonoma before 14.8.5
- Apple macOS Tahoe before 26.4
Timeline
- 2026-03-24: patched: Fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4
- 2026-03-25: disclosed: Initial NVD publication