Junglewise Threat Intelligence

CVE-2026-28978: Apple macOS sandbox escape in Installer

CVE-2026-28978 · Severity: high · CVSS 8.8 · Published 2026-05-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security vulnerability in the macOS Installer could allow a malicious application to bypass built-in security protections. Specifically, an app could break out of its restricted 'sandbox' environment to access parts of the system it should not be able to reach. This could lead to unauthorized data access or full system compromise if a user runs a malicious program.

Technical details

A permissions vulnerability exists in the macOS Installer component due to insufficient restrictions on process execution or file system access. A malicious, sandboxed application can exploit this logic flaw to break out of its sandbox container and gain unauthorized access to the broader operating system. The issue was addressed by implementing additional permission restrictions within the Installer framework. The vulnerability is reachable locally if a user executes a specially crafted malicious application. Patches are available in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.

Affected products

  • Apple macOS Sequoia before 15.7.7
  • Apple macOS Sonoma before 14.8.7
  • Apple macOS Tahoe before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats