Microsoft disclosed CVE-2022-26706, a macOS App Sandbox escape that allowed specially crafted code to bypass sandbox restrictions and execute unrestricted commands on a host. The flaw was uncovered during research into malicious macro execution in Microsoft Office on macOS, where Word’s ability to read or write files with the ~$ prefix could be chained with macOS Launch Services and the open --stdin option to launch a crafted Python file outside the sandbox. Microsoft reported the issue to Apple in October 2021, and Apple addressed it in security updates released in May 2022.
The vulnerability is significant because Launch Services and related macOS startup mechanisms have repeatedly appeared in real-world malware tradecraft. MITRE ATT&CK documents LaunchAgent persistence under T1543.001, noting widespread abuse of plist files in locations such as ~/Library/LaunchAgents and /Library/LaunchAgents by malware including Bundlore, FruitFly, Proton, ThiefQuest, and CookieMiner. Microsoft said its Defender for Endpoint detections remained effective against multiple Launch Services-based sandbox escape variants, underscoring the defensive value of monitoring for suspicious LaunchAgent creation and unexpected child-process execution from sandboxed applications.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft publicly disclosed technical details of CVE-2022-26706, explaining how a crafted Python file with an "~$" prefix could be executed outside Word's sandbox via open --stdin and Launch Services. The write-up also credited researcher Arsenii Kostromin and noted Defender detections remained effective against related variants.
Apple included a fix for CVE-2022-26706 in security updates released on May 16, 2022. The vulnerability allowed specially crafted code to bypass macOS App Sandbox restrictions and execute unrestricted commands.
In October 2021, Perception Point published a similar macOS sandbox escape later identified as CVE-2021-30864. Its technique used open with the --env option to override HOME so Terminal's zsh would execute a planted .zshenv file from a sandbox container directory.
Microsoft disclosed the macOS App Sandbox escape vulnerability later tracked as CVE-2022-26706 to Apple through coordinated vulnerability disclosure. The report followed Microsoft research into malicious macro execution in Office on macOS.
Several blog posts in 2020 described a generic macOS sandbox escape technique involving the /usr/bin/open utility and Launch Services. These prior techniques informed later research into Office-on-macOS sandbox bypasses.
In 2018, MDSec reported a macOS sandbox escape affecting Office in which Word could write specially named files into sensitive directories such as LaunchAgents. Microsoft later deployed a fix to block writes to LaunchAgents and similar folders.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.