ZeroHour

CVE-2026-84535

mass

macOS Sandbox Escape via Improper Authorization in Sequoia, Tahoe, Golden Gate

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-84535 is an improper access control flaw (CWE-284) in macOS stemming from broken state management during authorization checks, allowing a malicious application to break out of the App Sandbox. Exploitation is local: an attacker must get a victim to open or run a crafted app (user interaction required, no privileges needed), after which the app escapes sandbox confinement and can read and modify data beyond its container with high confidentiality and integrity impact across the compromised scope. All Macs running macOS versions prior to the fixed releases are affected, with a CVSS 3.1 base score of 8.2 (high). No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so no in-the-wild exploitation is currently known.

What to do: Patch promptly: update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > General > Software Update. Because exploitation requires the user to open a malicious app, enforce Gatekeeper/notarization checks and discourage running software from untrusted sources. Enterprise fleet managers should verify patch compliance across all Macs, since a successful escape grants the app access to sensitive user data outside its sandbox.

Affected
Apple macOS Sequoiaversions prior to 15.8
Apple macOS Tahoeversions prior to 26.7
Apple macOS Golden Gateversions prior to 27
Estimated exposure
mass≈tens of millions of unpatched Macs (subset of Apple's 100M+ active Mac install base) — Apple's publicly reported active Mac installed base is on the order of 100 million-plus devices, and any of them not yet on Sequoia 15.8, Tahoe 26.7, or Golden Gate 27 remain exposed — an estimate, not a measured count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.

Weakness
CWE-284
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.