CVE-2026-28838
Sandbox Escape Vulnerability in macOS Due to Permissions Issue
Publication date: 2026-03-25
Last updated on: 2026-03-25
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | macos | From 14.0 (inc) to 14.8.5 (exc) |
| apple | macos | From 15.0 (inc) to 15.7.5 (exc) |
| apple | macos | From 26.0 (inc) to 26.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a permissions issue in certain versions of macOS where an application may be able to break out of its sandbox. The sandbox is a security mechanism that restricts what an app can do and access. The issue was addressed by adding additional sandbox restrictions in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an application to escape its sandbox restrictions, potentially gaining unauthorized access to system resources or data that it should not have access to. This could lead to security breaches, data leaks, or unauthorized actions on the affected macOS system.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
I don't know
How can this vulnerability be detected on my network or system? Can you suggest some commands?
I don't know
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update your macOS system to one of the fixed versions: macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, or macOS Tahoe 26.4.