Executive brief
A security vulnerability in Apple's App Intents framework could allow a malicious application to escape its restricted environment, known as a sandbox. In a typical scenario, the sandbox prevents apps from accessing data or system resources they aren't authorized to use; a breakout could lead to unauthorized access to sensitive user information or system control. This issue affects a wide range of Apple devices including iPhones, iPads, Macs, and Apple Watches.
Technical details
A logic vulnerability exists within the App Intents framework across multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS). The flaw allows a locally installed malicious application to bypass sandbox restrictions, potentially gaining unauthorized access to system resources or user data outside of the app's intended container. Apple addressed the issue by implementing improved restrictions within the affected component. The vulnerability is fixed in iOS/iPadOS 18.7.9, iOS/iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory