Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
Published: 2026-07-27
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization flaw was discovered in macOS state management, enabling a malicious application to escape its sandbox. The vulnerability arises from improper handling of authorization state, allowing code to execute outside of the sandbox boundaries and potentially gain full system access. This represents a high-impact access control weakness, classified under CWE-284.

Affected Systems

Apple’s macOS operating system is affected, specifically versions prior to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. The issue is fixed in those releases.

Risk and Exploitability

The EPSS score is below 1%, indicating a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. However, because the flaw can break sandbox isolation, its impact remains high. Exploitation requires a malicious application to be executed on the target machine, suggesting a local attack vector that could advance from sandbox constraints to full system compromise. Until the relevant updates are installed, the risk is considered high for any user who may run untrusted applications.

Generated by OpenCVE AI on August 4, 2026 at 13:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the macOS update that contains the fix—Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6—without delay.
  • Verify that all installed applications are properly code‑signed and abide by sandbox policies; quarantine or remove any unsigned or suspicious programs.
  • Continue to apply all Apple security updates and monitor advisories for related authorization or sandbox weaknesses.

Generated by OpenCVE AI on August 4, 2026 at 13:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Improper Authorization State in macOS

Mon, 03 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Escape via Authorization State Management Vulnerability
Weaknesses CWE-285

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Escape via Authorization State Management Vulnerability
Weaknesses CWE-284
CWE-285
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:16:38.168Z

Reserved: 2026-07-20T18:09:54.848Z

Link: CVE-2026-64737

cve-icon Vulnrichment

Updated: 2026-07-28T14:16:33.969Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:12.573

Modified: 2026-07-28T18:00:10.010

Link: CVE-2026-64737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:15:03Z

Weaknesses