PT-2026-27563 · Apple · Macos Sonoma+3

Published

2026-03-24

·

Updated

2026-04-15

·

CVE-2026-28827

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to Sequoia 15.7.5 macOS versions prior to Sonoma 14.8.5 macOS versions prior to Tahoe 26.4
Description A flaw exists in how the operating system parses directory paths, potentially allowing an application to escape its designated sandbox. Improved path validation was implemented to address this issue.
Recommendations Update to macOS Sequoia version 15.7.5 or later. Update to macOS Sonoma version 14.8.5 or later. Update to macOS Tahoe version 26.4 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-28827

Affected Products

Apple Macos
Macos Sequoia
Macos Sonoma
Macos Tahoe