Executive brief
macOS enforces a sandbox to isolate applications and prevent them from accessing sensitive system resources and user data. A logic flaw in the sandboxing mechanism allows a malicious app to break out of its sandbox and gain unrestricted access to the system, potentially compromising all user data and system integrity.
Technical details
A logic issue in macOS Golden Gate's sandbox enforcement mechanism allows an app to circumvent sandboxing restrictions and escape containment. The vulnerability requires a malicious application to be installed and executed on the target system, exploiting improved checks that were insufficient in earlier versions. Successful exploitation grants an attacker local code execution with the privileges needed to access protected system resources and user data that the sandbox normally restricts. The issue is patched in macOS Golden Gate 27 with improved validation checks.
Affected products
- Apple macOS Golden Gate before 27
Timeline
- 2026-09-14: patched: Fixed in macOS Golden Gate 27