Impact
A logic flaw in Apple macOS allows a malicious application to escape its sandbox, potentially gaining unrestricted access to system resources. This weakness is rooted in insufficient checks during application execution, creating a pathway for code to run outside the sandbox boundary. The resulting compromise threatens confidentiality, integrity, and availability by letting the app read or modify any file or process that the user has permission for.
Affected Systems
The vulnerability affects Apple macOS releases including Golden Gate 27, Sequoia 15.8, and Tahoe 26.7, as well as any earlier versions that have not applied the update. All users running these operating systems are potentially exposed until the update is applied.
Risk and Exploitability
The CVSS score of 8.8 denotes a high‑severity vulnerability. The EPSS score of <1 % indicates that, as of the data, exploitation is estimated to be unlikely. The flaw is not listed in the CISA KEV catalog. The description only notes that an application may escape its sandbox; it does not specify how the attacker would gain the needed code execution or whether remote delivery is possible. Based on the type of sandbox escape, it is inferred that a local attacker who can supply malicious code to the system would be able to exploit the flaw, but no direct remote attack vector is documented in the provided material.
OpenCVE Enrichment