Junglewise Threat Intelligence

CVE-2026-84578: Apple macOS sandbox escape via logic issue

CVE-2026-84578 · Severity: high · CVSS 8.8 · Published 2026-09-14

Technologies: Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

macOS is Apple's operating system that runs on Mac computers and enforces security boundaries to prevent applications from accessing system resources outside their intended scope. A logic flaw in the sandbox enforcement mechanism allows a malicious application to escape its sandbox and gain unauthorized access to sensitive system resources and user data, compromising the integrity of the entire system.

Technical details

This vulnerability is a logic issue in macOS sandbox enforcement that was addressed through improved validation checks. The vulnerability allows an application to break out of its sandbox by exploiting the flaw in the sandbox validation logic. No specific authentication is required—a local attacker simply needs to run a malicious application on the system. An attacker can achieve unauthorized access to system resources and user data by circumventing sandbox restrictions. The issue is patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate prior to 27
  • Apple macOS Sequoia prior to 15.8
  • Apple macOS Tahoe prior to 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7

References

Related threats