Impact
The vulnerability is a logic flaw that allows a malicious application to escape its sandbox, granting it elevated privileges. This flaw originates from insufficient restrictions in the operating system, enabling an app to access resources otherwise protected. The core weakness matches CWE-269.
Affected Systems
Apple’s operating systems are impacted. The affected products are iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5. Systems running earlier versions remain vulnerable.
Risk and Exploitability
The risk is elevated because a sandbox escape enables arbitrary code execution across the system with the privileges of the executing user. EPSS score < 1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of publicly known exploits does not reduce the threat of local malicious apps. The CVSS score of 8.8 indicates high severity. Exploitation would require the attacker to develop or compromise an app and deploy it to the device, potentially through the App Store or sideloaded packages.
OpenCVE Enrichment