Executive brief
A security vulnerability in macOS could allow a malicious application to bypass built-in security restrictions known as the sandbox. Normally, the sandbox limits what an app can access to protect your personal files and system settings; a breakout could allow an app to access data it should not have permission to see. This issue is resolved in the latest macOS updates.
Technical details
A sandbox escape vulnerability exists in macOS Sequoia, Sonoma, and Tahoe. The flaw stems from an unspecified access issue that allowed applications to bypass sandbox boundary restrictions. An attacker could exploit this by tricking a user into running a malicious application, which could then gain unauthorized access to system resources or user data outside of its intended environment. Apple addressed the issue by implementing stricter sandbox restrictions. The vulnerability is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory