Junglewise Threat Intelligence

CVE-2026-84535: Apple macOS sandbox escape in Automator

CVE-2026-84535 · Severity: high · CVSS 8.2 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS is the operating system used across Apple's Mac computers to run applications and manage system resources. An app can break out of its sandbox—the security boundary that isolates applications from each other and from sensitive system areas—through an authorization flaw, potentially allowing malicious applications to access other apps' data and system resources. This exposes users to data theft and unauthorized system access.

Technical details

The vulnerability is an authorization issue in the Automator component of macOS that allows an app to break out of its sandbox. The root cause is improper state management in authorization checks. An app running on the system can exploit this flaw to bypass sandbox restrictions without requiring user interaction or elevated privileges. A successful exploit grants an attacker the ability to access resources outside the app's intended isolation boundary, including data from other applications and potentially sensitive system areas. Patches are available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats