Impact
The vulnerability is a logic flaw that allows a malicious application to escape its sandbox, granting it elevated privileges. The flaw arises because prior restrictions were insufficient, which has now been addressed with improved restrictions in the patched operating system versions. This issue enables an app to access resources that should otherwise be protected.
Affected Systems
Apple’s operating systems are impacted. The affected products are iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5. Systems running earlier versions remain vulnerable.
Risk and Exploitability
The risk is elevated because a sandbox escape enables arbitrary code execution across the system with the privileges of the executing user. EPSS score < 1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of publicly known exploits does not reduce the threat of local malicious apps. The CVSS score of 8.8 indicates high severity. Exploitation would require the attacker to develop or compromise an app and deploy it to the device, potentially through the App Store or sideloaded packages.
OpenCVE Enrichment