Junglewise Threat Intelligence

CVE-2026-28838: A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, ma

CVE-2026-28838 · Severity: medium · CVSS 5.3 · Published 2026-03-25

Technologies: Apple macOS Tahoe. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to bypass its built-in security restrictions, known as a sandbox. This could allow an app to access data or system resources it is not authorized to reach, potentially compromising user privacy or system integrity. Users should update to the latest versions of macOS to resolve this issue.

Technical details

A permissions issue existed within the CoreServices component of macOS. The vulnerability was caused by insufficient sandbox restrictions, which could be exploited by a malicious application to escape its sandbox environment. Successful exploitation allows an app to perform actions or access data outside of its intended isolation. Apple addressed the issue by implementing additional sandbox restrictions. The fix is available in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4.

Affected products

  • Apple macOS Sequoia before 15.7.5
  • Apple macOS Sonoma before 14.8.5
  • Apple macOS Tahoe before 26.4

Timeline

  • 2026-03-24: disclosed: Initial disclosure by Apple
  • 2026-03-24: patched: Patches released in macOS 15.7.5, 14.8.5, and 26.4
  • 2026-03-25: advisory: NVD publication date

References