Impact
A logic issue in macOS caused by an oversight in level checks allowed an application to escape its sandbox. The flaw is addressed with improved checks, and the issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.2. An app may be able to break out of its sandbox, potentially granting unauthorized system access and harming confidentiality, integrity, and availability.
Affected Systems
Apple macOS Sequoia versions earlier than 15.7.4, macOS Sonoma versions earlier than 14.8.4, and macOS Tahoe versions earlier than 26.2 are affected. The fix was introduced in those releases, so all installations running earlier versions are susceptible.
Risk and Exploitability
The vulnerability received a CVSS score of 8.4, indicating high severity, yet its EPSS score is below 1% and it is not listed in the CISA KEV catalog, implying a low probability of exploitation. The likely attack vector is an app that has already been installed or run on the vulnerable system; once executed, the logic issue could be leveraged to escape the sandbox and conduct further malicious activity.
OpenCVE Enrichment