Sandbox Escape Vulnerability in macOS Sequoia by Apple
CVE-2025-31195

6.3MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
12 May 2025

What is CVE-2025-31195?

A vulnerability has been identified in macOS Sequoia that enables applications to potentially escape their designated sandbox environment. This can lead to unauthorized access to system resources and compromise the security model designed to isolate applications. The issue has been addressed in version 15.4 of macOS Sequoia, which introduces additional logic to reinforce sandbox protections and prevent such breaches.

Affected Version(s)

macOS < 15.4

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.