Executive brief
A security vulnerability in macOS GPU drivers could allow a malicious application to escape its restricted environment, known as a sandbox. This could permit an attacker to gain unauthorized access to sensitive system resources or user data beyond what the app is normally allowed to see. Users should update to the latest versions of macOS to protect their systems from this potential compromise.
Technical details
A logging vulnerability exists within the macOS GPU Drivers component due to insufficient data redaction. A malicious application, even when restricted by the system sandbox, can exploit this flaw to achieve a sandbox escape. The root cause is a failure to properly sanitize or redact sensitive information in system logs, which can be leveraged to bypass security boundaries. Apple has addressed this issue in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5 by implementing improved data redaction mechanisms. Exploitation requires a user to run a malicious application on the affected system.
Affected products
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory