ZeroHour

CVE-2026-86894

mass

macOS Sandbox Escape Logic Flaw Fixed in macOS Golden Gate 27

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-86894 is a sandbox escape in macOS caused by a logic flaw (a protection mechanism failure, CWE-693) that Apple addressed with improved checks. It is triggered by an app already running on the system abusing the flawed validation to break out of its sandbox confinement, so practical exploitation requires the attacker to first get a malicious or compromised app onto the target Mac, or to compromise an existing app. A successful escape undermines the sandbox boundary and, per the CVSS 3.1 vector (7.5, integrity impact high), allows the app to modify data outside its intended container. All macOS versions prior to Golden Gate 27 are affected; the fix ships in macOS Golden Gate 27. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of in-the-wild exploitation.

What to do: Update all Macs to macOS Golden Gate 27 or later as soon as it is available, prioritizing systems that run non-App Store or non-notarized applications. Review recently installed third-party apps and browser extensions for suspicious behavior, since exploitation requires a malicious or already-compromised app on the endpoint. Keep Gatekeeper and notarization enforcement enabled to reduce the chance of untrusted code running in the first place.

Affected
Apple macOS (Golden Gate)All versions prior to macOS Golden Gate 27 (fixed in macOS Golden Gate 27)
Estimated exposure
massOn the order of tens to hundreds of millions of Macs, declining as users update — Apple's macOS installed base is on the order of 100M+ active devices globally, and the affected range is every macOS version prior to Golden Gate 27, so plausibly well over 1M unpatched systems at disclosure; this is an estimate only.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.

Weakness
CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.