Description
A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.
Published: 2026-07-27
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw in macOS allows an application to access files outside its sandboxed environment. This vulnerability could enable an attacker to read or modify sensitive data that should be restricted to the sandbox, effectively eroding the isolation boundaries that macOS enforces for applications. The weakness is classified as a classic path traversal issue, compromising confidentiality and potentially integrity of protected files.

Affected Systems

Apple macOS is affected. The defect is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Any earlier releases of these macOS versions that have not applied these updates remain vulnerable.

Risk and Exploitability

The vulnerability was addressed by improved input validation; the EPSS score is < 1% and KEV is not listed, indicating limited public exploitation data. The likely attack vector is local, requiring the attacker to run a malicious application or exploit the flaw in a legitimate application that runs with user privileges. Without a published exploit or high EPSS score, the risk is moderate but still significant enough to warrant patching.

Generated by OpenCVE AI on August 4, 2026 at 13:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the macOS update that includes the fix for CVE-2026-43772 (Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6).
  • Reboot the system to ensure the updated kernel and sandbox mechanisms are active.
  • Temporarily disable or uninstall any application that may trigger the path traversal flaw until the OS update is applied.

Generated by OpenCVE AI on August 4, 2026 at 13:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title macOS Path Traversal Allows Sandbox Breakout

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title macOS Path Traversal Allows Sandbox Breakout
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:13:17.492Z

Reserved: 2026-05-01T22:46:27.818Z

Link: CVE-2026-43772

cve-icon Vulnrichment

Updated: 2026-07-28T15:13:12.845Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:01.573

Modified: 2026-07-28T18:07:07.193

Link: CVE-2026-43772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')