Apple disclosed two high-severity macOS vulnerabilities, CVE-2026-28891 and CVE-2026-28817, that could allow an application or sandboxed process to escape sandbox restrictions. Both flaws were attributed to race conditions, classified as CWE-362, and carried the same CVSS v3.1 vector: AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating local exploitation with potentially severe impact to confidentiality, integrity, and availability.
Apple said the issues were remediated through additional validation and improved state handling. Fixes were released for macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4, and organizations running affected macOS systems should prioritize those updates because successful exploitation could let untrusted code break out of the sandbox and operate with broader system access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE entries were later updated to add CWE-362 classification and CVSS v3.1 scoring information, including the vector AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H. The updates characterized the bugs as local, high-impact vulnerabilities affecting confidentiality, integrity, and availability.
Apple said the vulnerabilities were addressed with improved state handling and additional validation in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4. These updates were identified as the fixes for the disclosed sandbox escape issues.
Apple disclosed CVE-2026-28817 and CVE-2026-28891, both race condition flaws that could allow a sandboxed app or process to escape sandbox restrictions on macOS. The CVE records were received from Apple's product security team and published on the same day.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.