
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28838 is a sandbox escape vulnerability in the CoreServices component of Apple macOS, where a permissions issue allows an app to break out of its sandbox environment. It affects macOS Sonoma versions before 14.8.5, macOS Sequoia versions before 15.7.5, and macOS Tahoe versions before 26.4. Apple disclosed and patched the vulnerability on March 24, 2026, crediting an anonymous researcher for the discovery. The CVSS v3.1 base score is 5.3 (Medium), though Feedly's category estimate rates it as HIGH (Apple Advisory Tahoe, Apple Advisory Sequoia, Apple Advisory Sonoma).
The vulnerability is rooted in improper access control (CWE-284) within the macOS CoreServices component, where insufficient sandbox permission enforcement allows a sandboxed application to escape its restricted execution environment. Apple addressed the issue by applying additional sandbox restrictions, indicating that the original sandbox policy failed to adequately constrain certain permissions or resource access paths. No public technical write-up or proof-of-concept code detailing the specific exploitation mechanics has been released as of the time of this report (Apple Advisory Tahoe, Apple Advisory Sequoia).
Successful exploitation allows a malicious application running within the macOS sandbox to escape its restricted environment and potentially access system resources, files, or processes that are normally protected by sandbox policies. This could enable an attacker to access sensitive user data, escalate privileges, or perform unauthorized actions on the host system beyond what the sandboxed app is permitted. The integrity and confidentiality of the system are the primary concerns, as sandbox escapes can serve as a stepping stone for further compromise or lateral movement (Apple Advisory Tahoe, Apple Advisory Sonoma).
Apple has released patches addressing this vulnerability across all affected macOS versions. Users should update to macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, or macOS Tahoe 26.4 or later, all released on March 24, 2026. As an additional precaution, administrators should restrict the installation of untrusted or unverified applications and monitor for suspicious application behavior attempting to access resources outside normal sandbox boundaries (Apple Advisory Tahoe, Apple Advisory Sequoia, Apple Advisory Sonoma).
The vulnerability was included in Apple's March 2026 security update batch, which addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS, drawing general coverage from security news outlets. The CIS published an advisory noting multiple vulnerabilities in Apple products that could allow for privilege escalation. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-28838 has been identified (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."