Apple WebKit Sandbox Bypass Vulnerability

Vulnerability

A race condition vulnerability has been identified in the WebKit component of Apple macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4. This vulnerability allows a sandboxed process to potentially circumvent sandbox restrictions, which could lead to unauthorized access or actions within the user's environment.

Impact

Exploitation of this vulnerability could allow a sandboxed process to break out of its sandbox, bypassing restrictions meant to isolate applications and protect system resources.

Reproduction

The vulnerability can be reproduced by creating a sandboxed process that interacts with the printing system. The race condition can be exploited by timing the interaction in such a way that the process circumvents the intended sandbox restrictions.

Remediation

Users can update to macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, or macOS Tahoe 26.4 to address this vulnerability.

Added: Mar 25, 2026, 2:59 AM
Updated: Mar 25, 2026, 2:59 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
3.2
remediation
8.3
relevance
4.7
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.