Apple Archive Utility Symlink Handling Vulnerability Allowing Sandbox Bypass

Vulnerability

A vulnerability in the Archive Utility component of macOS Sequoia 15.6 allows an application to break out of its sandbox. This issue arises from improper handling of symbolic links, which could be exploited by a malicious app to access restricted resources or perform unauthorized actions outside of its designated sandbox environment.

Impact

Exploitation of this vulnerability could lead to unauthorized access to system resources or data, allowing an app to operate outside of its sandbox restrictions.

Added: Apr 2, 2026, 8:43 PM
Updated: Apr 2, 2026, 8:43 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.8
exploitability
3.3
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.