Description
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path handling flaw in macOS allows a malicious application to bypass its sandbox, potentially granting the app elevated system privileges and the ability to execute code outside the intended restricted environment. The flaw arises from insufficient validation of file system paths, enabling the app to traverse or target disallowed locations. This weakness can lead to full compromise of the device if exploited, as the sandbox boundary is no longer enforced for the offending process.

Affected Systems

Apple macOS is affected, specifically the Sequoia and Tahoe lineages. Versions before Sequoia 15.7.8 and before Tahoe 26.6 are vulnerable, while these patched releases address the path validation bug. All earlier releases lacking the fix remain susceptible to sandbox escape.

Risk and Exploitability

The vulnerability is a severe privilege escalation cause, with potential for remote code execution if an attacker can install a malicious app on the target machine. The EPSS score is < 1%, indicating a very low probability of exploitation, and the issue is not currently listed in the CISA KEV catalog. The official advisory indicates that a malicious application may break out of its sandbox, suggesting local attack conditions. In the absence of selected exploitation data, the risk should be treated as high for any device running an affected macOS version.

Generated by OpenCVE AI on August 4, 2026 at 13:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest macOS update (Sequoia 15.7.8 or Tahoe 26.6 or newer) to obtain the fixed path handling validation.
  • Enable Gatekeeper and configure it to allow only applications from the App Store or identified developers, preventing unauthorized apps from executing.
  • Use MDM or automated patch management to ensure all macOS devices are promptly updated and monitor for compliance with the new release.

Generated by OpenCVE AI on August 4, 2026 at 13:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title macOS Path Handling Vulnerability Allows Sandbox Escape

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Path Handling Vulnerability in macOS
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Path Handling Vulnerability in macOS
Weaknesses CWE-22
CWE-284
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T13:46:13.871Z

Reserved: 2026-07-20T18:09:54.848Z

Link: CVE-2026-64731

cve-icon Vulnrichment

Updated: 2026-07-28T13:46:03.684Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:12.030

Modified: 2026-07-28T18:48:20.080

Link: CVE-2026-64731

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')