A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Sandbox Escape via Path Handling Vulnerability in macOS | |
| Weaknesses | CWE-22 CWE-284 |
|
| Metrics |
cvssV3_1
|
Tue, 28 Jul 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos |
|
| Vendors & Products |
Apple
Apple macos |
Mon, 27 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published: 2026-07-27T20:14:03.683Z
Updated: 2026-07-28T13:46:13.871Z
Reserved: 2026-07-20T18:09:54.848Z
Link: CVE-2026-64731
Updated: 2026-07-28T13:46:03.684Z
No data.
No data.