Description
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to bypass network restrictions.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient enforcement of sandbox permissions, allowing an application to bypass network restrictions that should be upheld by macOS. This permits the app to send or receive network traffic beyond its intended sandbox, potentially exposing sensitive data or violating network isolation policies. While no direct remote code execution is described, the impact on confidentiality and integrity of network communications is significant.

Affected Systems

Apple macOS releases are impacted, specifically macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Any version prior to these cumulative updates may still allow an application to escape sandbox network restrictions.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑high impact, and the EPSS score of < 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an application that can abuse sandbox permissions to access network services beyond its intended scope. An attacker with such an application could gain unauthorized network access, potentially leaking data or enabling lateral movement across the user’s network. The issue is resolved in the indicated software updates, so applying the fix removes the risk.

Generated by OpenCVE AI on August 3, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to at least version 15.7.8, 14.8.8, or 26.6, which contain the sandbox restriction fix.
  • Apply managed device policies (MDM) to enforce stricter network access controls for sandboxed applications.
  • Monitor network traffic for unexpected outbound connections from sandboxed apps and adjust firewall or application sandbox profiles accordingly.

Generated by OpenCVE AI on August 3, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Permissions Issue Enabling Network Restriction Bypass in macOS Sandbox

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Permissions Issue Enabling Network Restriction Bypass in macOS Sandbox
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to bypass network restrictions.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:40:14.723Z

Reserved: 2026-03-03T16:36:03.989Z

Link: CVE-2026-28945

cve-icon Vulnrichment

Updated: 2026-07-28T14:39:59.740Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:50.120

Modified: 2026-07-28T17:54:14.937

Link: CVE-2026-28945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:30:04Z

Weaknesses