Impact
The vulnerability is an improper state‑management flaw that allows an application to escape its sandbox, thereby gaining unrestricted access to system resources. By stepping outside the sandbox, the compromised application can modify or read any file, inject code, or run commands with the privileges of the current user, threatening confidentiality, integrity, and availability of the macOS system.
Affected Systems
Apple macOS versions older than macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected before the fix. The vulnerability is resolved by updating to one of these patched releases or later.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, implying a low likelihood of widespread exploitation. Nonetheless, a sandbox escape can enable privilege escalation. The likely scenario involves a malicious or compromised application running locally under a user’s credentials; the flaw allows that application to override sandbox restrictions. Because the description does not specify a remote trigger, it is inferred that local execution of a targeted app is required to exploit the issue.
OpenCVE Enrichment