Junglewise Threat Intelligence

CVE-2026-28945: Apple macOS network restriction bypass in Sandbox

CVE-2026-28945 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Tahoe. Vendors: Apple.

Executive brief

A security flaw in macOS could allow a malicious application to bypass established network restrictions. This means an app that should be blocked from accessing the internet or local network might be able to communicate externally, potentially leaking data or contacting malicious servers. Apple has released software updates to address this issue by strengthening the system's security sandbox.

Technical details

A permissions vulnerability exists within the macOS sandbox environment across multiple versions of the operating system. The flaw allows a locally installed application to circumvent network-related restrictions imposed by the system sandbox. The root cause was identified as insufficient sandbox enforcement, which Apple mitigated by introducing additional sandbox restrictions. An attacker would need to entice a user to install and run a malicious application to exploit this bypass. Successful exploitation allows the application to perform unauthorized network communications that should otherwise be prohibited by its profile.

Affected products

  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6

Timeline

  • 2026-07-27: disclosed: Initial publication of the CVE record and Apple security advisories.
  • 2026-07-27: patched: Fixes released in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.

References

Related threats