Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.
Published: 2026-09-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox escape potentially leading to privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper state‑management flaw that allows an application to escape its sandbox, thereby gaining unrestricted access to system resources. By stepping outside the sandbox, the compromised application can modify or read any file, inject code, or run commands with the privileges of the current user, threatening confidentiality, integrity, and availability of the macOS system.

Affected Systems

Apple macOS versions older than macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected before the fix. The vulnerability is resolved by updating to one of these patched releases or later.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, implying a low likelihood of widespread exploitation. Nonetheless, a sandbox escape can enable privilege escalation. The likely scenario involves a malicious or compromised application running locally under a user’s credentials; the flaw allows that application to override sandbox restrictions. Because the description does not specify a remote trigger, it is inferred that local execution of a targeted app is required to exploit the issue.

Generated by OpenCVE AI on September 20, 2026 at 18:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install macOS updates that include the authorization fix (macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 or later).
  • Verify that all third‑party applications are from trusted sources and consider disabling or uninstalling those that may be compromised.
  • Enable macOS System Integrity Protection and review sandbox audit logs for anomalous behavior.

Generated by OpenCVE AI on September 20, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Authorization flaw enables sandbox escape on macOS

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Authorization Issue Allows App to Break Out of Sandbox in macOS

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authorization Issue Allows App to Break Out of Sandbox in macOS
Weaknesses CWE-284

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T18:41:48.533Z

Reserved: 2026-09-01T21:13:17.750Z

Link: CVE-2026-84535

cve-icon Vulnrichment

Updated: 2026-09-15T18:41:44.757Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:29.950

Modified: 2026-09-16T18:02:05.460

Link: CVE-2026-84535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:45:02Z

Weaknesses