Description
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An application can break out of its sandbox due to improper access control, allowing it to execute code in an unintended environment. The flaw was mitigated by adding stricter sandbox restrictions in macOS Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. The weakness corresponds to CWE‑284, Incorrect Access Control.

Affected Systems

Apple macOS versions older than Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6 are vulnerable. Systems running earlier builds of these releases may allow a malicious or compromised application to escape its sandbox and potentially access protected system resources or user data.

Risk and Exploitability

The CVSS score of 9.8 marks this vulnerability as critical. An EPSS score of < 1 % and its absence from the CISA KEV catalog suggest that exploitation is currently unlikely, yet the possibility of privilege escalation makes immediate remediation necessary. An attacker would need to deliver or run a malicious application that takes advantage of the insufficient sandbox restriction, potentially via social engineering or by submitting an application signed with a trusted certificate. No publicly disclosed exploits are known, but the high severity warrants rapid patching.

Generated by OpenCVE AI on August 12, 2026 at 12:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to macOS Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6 to receive the sandbox restriction fix
  • Only permit installation of applications from trusted, signed sources; enforce this by configuring System Preferences > Security & Privacy > App Store & identified developers
  • Monitor system logs for sandbox violation entries and report any incidents to Apple’s support channels

Generated by OpenCVE AI on August 12, 2026 at 12:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Escape via Improper Access Control

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Escape via Improper Access Control
Weaknesses CWE-284

Wed, 05 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Breakout Vulnerability Allowing Apps to Escape Sandbox
Weaknesses CWE-269
CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Breakout Vulnerability Allowing Apps to Escape Sandbox
Weaknesses CWE-269
CWE-284

Tue, 28 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T18:40:13.829Z

Reserved: 2026-07-20T18:09:24.049Z

Link: CVE-2026-64702

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:09.780

Modified: 2026-07-30T14:35:03.203

Link: CVE-2026-64702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:15:04Z

Weaknesses