Executive brief
A sandbox sandbox security restriction in macOS can be bypassed to allow an application to access sensitive user data that should be protected. This affects multiple recent versions of Apple's operating system and could allow a malicious app to read private information without user authorization or knowledge.
Technical details
The vulnerability is an access control issue where additional sandbox restrictions were needed to properly protect user-sensitive data. The root cause is insufficient isolation between applications and protected user information. An attacker can create a malicious app that exploits this sandbox weakness to gain unauthorized access to sensitive data. The attack requires the victim to run a malicious application on their Mac but does not require network access or user interaction beyond installation. Apple addressed this issue by implementing additional sandbox restrictions in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7