Junglewise Threat Intelligence

CVE-2026-65381: Apple macOS sandbox escape in entitlement verification

CVE-2026-65381 · Severity: critical · CVSS 10 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A validation flaw in macOS entitlement verification allows malicious applications to escape their sandbox restrictions. This issue affects multiple versions of macOS (Golden Gate 27, Sequoia 15.8, and Tahoe 26.7) and has been patched. Successful exploitation would allow a hostile app to access system resources and data outside its intended confinement, potentially compromising user data and system integrity.

Technical details

A validation issue in the process entitlement verification logic allowed malicious applications to circumvent sandbox restrictions. The vulnerability is an authorization/validation bypass affecting the AppleMobileFileIntegrity component (or broader sandbox enforcement). No special preconditions are required beyond the attacker distributing a malicious app; exploitation requires local execution of the crafted application. The vulnerability was patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 through improved validation of process entitlements.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats