Junglewise Threat Intelligence

CVE-2026-43763: Apple macOS sandbox escape via permissions issue

CVE-2026-43763 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Tahoe. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to bypass its restricted environment (sandbox) to read sensitive files on the system. This could lead to the unauthorized exposure of user data or system information that the app should not have access to. Apple has addressed this issue in the latest updates for macOS Sequoia, Sonoma, and Tahoe.

Technical details

A permissions vulnerability exists in macOS that allows for a sandbox escape. Specifically, a malicious application may be able to read files outside of its sandbox container due to an underlying permissions issue. The vulnerability was addressed by Apple through the removal of the affected code. The attack requires a local malicious application to be present on the system. Patches are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.

Affected products

  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats