Impact
A flaw in macOS sandbox enforcement—identified as CWE‑284—allows a compromised or malicious application to exit its intended confined environment and access system resources beyond its permissions. This can expose private data, modify system files, or execute code with higher privileges, thereby jeopardizing the confidentiality, integrity, and availability of the host system.
Affected Systems
Apple macOS Sequoia, macOS Sonoma, and macOS Tahoe are affected. Distributions prior to macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.2 contain the vulnerability. The exact version range is not specified, but any build older than the listed patches is vulnerable.
Risk and Exploitability
The issue is described as an access violation that can lead to sandbox breakout; no EPSS score is available and it is not listed in the CISA KEV catalog. Because the vulnerability requires a local application to exercise the flaw, the attack vector is inferred to be local or remote via a malicious app. While no public exploits are currently cited, the potential for full system compromise makes this a high‑threat escalation vector that should be treated with urgency. The CVSS score of 8.8 indicates a high severity.
OpenCVE Enrichment