Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.
Published: 2025-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox Escape / Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A permissions issue in macOS, addressed by adding further restrictions, can allow an application to break out of its sandbox. The flaw is an authorization bypass that grants excessive privileges to the sandboxed process, enabling code execution beyond the intended confinement boundaries. This type of weakness can allow an attacker to compromise system integrity and confidentiality by running code with elevated privileges.

Affected Systems

The vulnerability affects systems running Apple macOS before macOS Tahoe 26. This includes all earlier macOS releases where the sandbox permission checks were insufficient. The patch is delivered in macOS Tahoe 26, thus users on earlier macOS versions are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity of the flaw. The EPSS score of < 1% suggests that exploitation is currently rare, and the vulnerability is not listed in CISA KEV, which further reduces the likelihood of current active attacks. The likely attack vector is local, requiring the malicious application to be executed on the targeted machine with the ability to request elevated permissions during sandbox setup. Given the high potential impact and low exploitation probability, stakeholders should plan remediation promptly.

Generated by OpenCVE AI on April 28, 2026 at 00:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the operating system to macOS Tahoe 26 or later to receive the vendor fix that restores proper permission checks.
  • If an upgrade is not immediately possible, audit the sandbox configuration and remove any unnecessary entitlements or file access permissions for the affected application to reduce the surface area of escape.
  • Enable Gatekeeper, enforce app notarization, and limit network and file system permissions for all applications until the patch is applied, thereby limiting the ability of a malicious app to escape the sandbox.

Generated by OpenCVE AI on April 28, 2026 at 00:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-29329 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.
History

Tue, 28 Apr 2026 00:30:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Escape via Permission Misconfiguration

Mon, 03 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
References

Wed, 17 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 17 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Tue, 16 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Mon, 15 Sep 2025 22:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:12:44.341Z

Reserved: 2025-04-16T15:24:37.110Z

Link: CVE-2025-43340

cve-icon Vulnrichment

Updated: 2025-09-16T18:13:00.331Z

cve-icon NVD

Status : Modified

Published: 2025-09-15T23:15:36.273

Modified: 2025-11-03T19:16:02.230

Link: CVE-2025-43340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T00:15:05Z

Weaknesses