CVE-2025-46297
macOS vulnerability analysis and mitigation

Overview

CVE-2025-46297 is a permissions issue in Apple macOS that allows an app to access protected files within an App Sandbox container. The vulnerability was discovered by Mickey Jin (@patch1t) and disclosed on December 12, 2025, with the CVE entry added to Apple's advisory on January 9, 2026. It affects macOS Tahoe versions prior to 26.2 and is fixed in macOS Tahoe 26.2. The CVSS v3.1 base score is 5.5 (Medium), reflecting a local attack vector with high confidentiality impact but no integrity or availability impact (Apple Advisory).

Technical details

The root cause is classified as CWE-284 (Improper Access Control), specifically a permissions issue in the AppSandbox component of macOS Tahoe. Apple addressed the flaw by applying additional restrictions to the permissions handling logic. Exploitation requires local access and user interaction, meaning a malicious app running on the target system could leverage this flaw to read files that should be protected by the App Sandbox boundary. No public technical write-up or proof-of-concept code has been identified beyond Apple's advisory (Apple Advisory).

Impact

Successful exploitation allows a sandboxed application to access protected files within another App Sandbox container, resulting in unauthorized disclosure of sensitive data. The confidentiality impact is rated High, while integrity and availability are unaffected. The scope is limited to the local system, but the ability to break sandbox isolation could expose sensitive user files or application data that would otherwise be inaccessible to the attacking app (Apple Advisory).

Mitigation and workarounds

Apple has released a fix in macOS Tahoe 26.2, released December 12, 2025. Users and administrators should update to macOS Tahoe 26.2 or later to remediate this vulnerability. No configuration-based workarounds have been published; upgrading to the patched release is the only recommended remediation (Apple Advisory).

Community reactions

The vulnerability was credited to security researcher Mickey Jin (@patch1t), a well-known macOS security researcher who regularly discovers sandbox and privilege escalation issues on Apple platforms. No significant broader media coverage or notable community commentary beyond the standard advisory acknowledgment has been identified for this specific CVE.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management