Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes a permissions issue that allows a malicious application to break out of its sandbox confinement, potentially undermining the isolation guarantees provided by macOS, iOS, and iPadOS.

Affected Systems

Apple's macOS operating system is affected. Versions of macOS Sequoia, Sonoma, and Tahoe that precede 15.7.8, 14.8.8, and 26.6 respectively remain vulnerable, while the patched releases 15.7.8, 14.8.8, and 26.6 contain the fix. The same vulnerability also applies to iOS and iPadOS. Versions prior to iOS 18.7.10 and iPadOS 18.7.10 are vulnerable.

Risk and Exploitability

The CVSS score of 9.8 highlights a critical severity, but the EPSS below 1% suggests only a low probability of active exploitation in the wild. The vulnerability is not listed in CISA KEV. Based on the description, a malicious application that obtains elevated permissions can potentially escape its sandbox, indicating a local attack vector that requires the attacker to run a compromised app on the target machine. No publicly disclosed exploit code is available, so the risk hinges on the likelihood of such an app being installed.

Generated by OpenCVE AI on August 17, 2026 at 23:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the macOS update to Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6 or later to eliminate the flaw.
  • If an upgrade is not feasible, use Gatekeeper, MDM profiles, or local security policies to restrict the installation and execution of unsigned or untrusted applications.
  • Monitor system logs for unexpected sandbox escape attempts or unauthorized resource access, and enforce strict application signing requirements.

Generated by OpenCVE AI on August 17, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Sandbox Breakout via Permissions Issue in macOS

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox. A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
References

Wed, 05 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Sandbox Breakout via Permissions Issue in macOS

Sun, 02 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Escape via Permissions Issue
Weaknesses CWE-285
CWE-290

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Escape via Permissions Issue
Weaknesses CWE-285
CWE-290

Tue, 28 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:20.269Z

Reserved: 2026-07-20T18:09:54.848Z

Link: CVE-2026-64738

cve-icon Vulnrichment

Updated: 2026-07-28T16:23:31.985Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:12.677

Modified: 2026-08-17T22:17:19.187

Link: CVE-2026-64738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:30:04Z

Weaknesses