Impact
A path handling flaw in macOS allows a malicious application to bypass its sandbox, potentially granting the app elevated system privileges and the ability to execute code outside the intended restricted environment. The flaw arises from insufficient validation of file system paths, enabling the app to traverse or target disallowed locations. This weakness can lead to full compromise of the device if exploited, as the sandbox boundary is no longer enforced for the offending process.
Affected Systems
Apple macOS is affected, specifically the Sequoia and Tahoe lineages. Versions before Sequoia 15.7.8 and before Tahoe 26.6 are vulnerable, while these patched releases address the path validation bug. All earlier releases lacking the fix remain susceptible to sandbox escape.
Risk and Exploitability
The vulnerability is a severe privilege escalation cause, with potential for remote code execution if an attacker can install a malicious app on the target machine. The EPSS score is < 1%, indicating a very low probability of exploitation, and the issue is not currently listed in the CISA KEV catalog. The official advisory indicates that a malicious application may break out of its sandbox, suggesting local attack conditions. In the absence of selected exploitation data, the risk should be treated as high for any device running an affected macOS version.
OpenCVE Enrichment