Description
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.
Published: 2026-09-14
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox Breakout
Action: Upgrade OS
AI Analysis

Impact

This issue stems from the operating system’s handling of symbolic links, allowing a sandboxed application to resolve links that point to protected system files or directories. The result is a privilege‑escalation flaw that lets the app exceed its sandboxed boundaries. This vulnerability is an example of CWE-59, in which symbolic‑link abuse allows the resolution of paths that should be inaccessible.

Affected Systems

Apple macOS installations that have not yet been updated to macOS Golden Gate 27 or later are affected. The flaw was fixed in that release, so any version older than 27 remains susceptible for applications that create or interact with symbolic links.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, yet the risk is substantial because sandbox breakout can grant local processes higher privileges. The CVSS score of 8.4 indicates a high severity vulnerability. The likely attack vector is local; an attacker must be able to influence the symlink a sandboxed application resolves, perhaps by placing a malicious link in a location the app accesses. If such a link is crafted, the application can access files or directories outside its sandbox, compromising confidentiality or integrity of protected system resources.

Generated by OpenCVE AI on September 20, 2026 at 20:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to macOS Golden Gate 27 or later to apply the official symlink‑handling fix.
  • Restrict the target application’s ability to create or resolve symbolic links by tightening its sandbox profile or applying additional filesystem access controls.
  • Monitor system logs for abnormal symlink usage or unauthorized file accesses by the application and investigate any suspicious activity promptly.

Generated by OpenCVE AI on September 20, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Symlink Handling Failure Enables Sandbox Breakout on macOS

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-59
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Symlink Handling Improves Allowing Sandbox Breakout in macOS
Weaknesses CWE-22
CWE-363

Tue, 15 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Symlink Handling Improves Allowing Sandbox Breakout in macOS
Weaknesses CWE-22
CWE-363

Tue, 15 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T17:20:45.568Z

Reserved: 2026-09-01T21:13:17.757Z

Link: CVE-2026-84584

cve-icon Vulnrichment

Updated: 2026-09-17T17:20:26.279Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:34.480

Modified: 2026-09-17T18:17:10.893

Link: CVE-2026-84584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:15:04Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')