Apple NSColorPanel Sandbox Escape Vulnerability

Vulnerability

A logic issue allowing a malicious app to break out of its sandbox has been identified in the NSColorPanel component of macOS Tahoe, prior to 26.4. This vulnerability was addressed with improved restrictions.

Impact

Exploitation of this vulnerability could lead to unauthorized access to system resources or user data by allowing an app to escape its sandboxed environment.

Remediation

Users can update to macOS Tahoe 26.4 to address this vulnerability.

Added: Mar 25, 2026, 2:16 AM
Updated: Mar 25, 2026, 2:16 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.