CVE-2025-43286

7.8

Apple · macOS

A sandbox escape vulnerability in macOS allows a local application to bypass security restrictions and achieve full system impact.

Executive summary

A high-severity sandbox escape vulnerability in Apple macOS allows a local, authenticated application to compromise the integrity and confidentiality of the host system.

Vulnerability

The flaw is a permissions-based sandbox breakout, where a local application with low privileges can circumvent the operating system isolation mechanisms. This allows the application to perform actions outside of its intended security boundary, effectively escalating its access level on the host system.

Business impact

Successful exploitation of this vulnerability permits a malicious or compromised application to escape its sandbox, leading to potential unauthorized access to sensitive user data, system-wide configuration changes, or the execution of arbitrary code with elevated privileges. Given the CVSS score of 7.8, this vulnerability poses a significant risk to organizational assets, as it undermines the primary security architecture designed to contain untrusted software.

Remediation

Immediate Action: Update all affected macOS installations to the patched versions: macOS Sequoia 15.7, macOS Sonoma 14.8, or macOS Tahoe 26.

Proactive Monitoring: Monitor system logs for unusual application behavior, specifically processes attempting to access files or services outside of their established user profile or sandbox directory.

Compensating Controls: Enforce strict application control policies to ensure that only authorized and verified software is executed, and utilize endpoint detection and response tools to identify unauthorized privilege escalation attempts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a critical failure in the macOS security model that could allow for full system compromise. Administrators should prioritize the deployment of the provided security updates across all managed Apple devices to close this security gap and prevent potential lateral movement or data exfiltration by malicious applications.

More Apple CVEs

Sources