Junglewise Threat Intelligence

CVE-2026-43772: Apple macOS path traversal sandbox escape

CVE-2026-43772 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Sequoia. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to bypass its security restrictions (sandbox). This could enable an app to access files or data it is not authorized to see, potentially compromising user privacy or system integrity. Apple has released software updates to address this issue across several versions of macOS.

Technical details

A path traversal vulnerability existed in macOS due to insufficient input validation. A malicious application could exploit this flaw to escape its sandbox environment and access files outside of its designated directory. The issue was mitigated by implementing improved input validation mechanisms. The vulnerability affects macOS Sequoia versions prior to 15.7.8, macOS Sonoma versions prior to 14.8.8, and macOS Tahoe versions prior to 26.6.

Affected products

  • Apple macOS Sequoia before 15.7.8
  • Apple macOS Sonoma before 14.8.8
  • Apple macOS Tahoe before 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats