CVE-2026-84578
Apple · macOS
A logic flaw in Apple macOS allows a sandboxed application to escape its security constraints, potentially leading to full system compromise.
Executive summary
A high-severity sandbox escape vulnerability in Apple macOS permits malicious applications to bypass security boundaries, posing a significant risk of unauthorized system-wide access.
Vulnerability
This vulnerability is a logic error in the macOS sandbox implementation. A local, low-privileged application can exploit these improved check failures to break out of its restricted environment and execute operations with higher privileges than intended.
Business impact
The ability for an application to escape the sandbox environment allows it to bypass critical security controls designed to isolate processes. Successful exploitation could lead to full unauthorized access to sensitive user data, system files, and escalated privileges, resulting in severe data breach potential and loss of system integrity. With a CVSS score of 8.8, this vulnerability represents a high-risk scenario that must be addressed immediately to prevent lateral movement within the host operating system.
Remediation
Immediate Action: Apply the vendor-provided security updates to macOS Sequoia (15.8), macOS Tahoe (26.7), or macOS Golden Gate (27) as soon as possible.
Proactive Monitoring: Review system logs for unusual process activity or unauthorized attempts to access protected directories that typically fall outside of standard application sandbox constraints.
Compensating Controls: Enforce strict application whitelisting policies and utilize endpoint detection and response (EDR) solutions to monitor for anomalous system calls originating from untrusted or sandboxed applications.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the high CVSS score and the potential for a complete sandbox breakout, organizations should prioritize patching all affected macOS endpoints. Administrators should verify that their systems are running the specified versions or newer to eliminate this logic flaw. Delaying deployment of these updates increases the risk of malicious software gaining persistent access to the underlying system environment.
More Apple CVEs all →
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written