• PATCH AVAILABLE

CVE-2026-65381: sandbox escape via entitlement validation in Apple macOS

An attacker who can run a malicious app on macOS may break out of the app sandbox and execute code outside its restrictions. CVE-2026-65381 is a validation problem in entitlement checking that can allow a sandbox escape. Affects macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27; an attacker needs to run a specially crafted app on the target system.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.00354
CWE
CWE-862
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgently install Apple’s updates: the vendor published fixes for the affected branches (15.8, 26.7, 27), so patching is the fastest way to remove the risk.

What is CVE-2026-65381?

An attacker who can run a malicious app on macOS may break out of the app sandbox and execute code outside its restrictions. CVE-2026-65381 is a validation problem in entitlement checking that can allow a sandbox escape. Affects macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27; an attacker needs to run a specially crafted app on the target system.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
15.xbefore 15.815.8
26.xbefore 26.726.7
27.xbefore 2727

Is CVE-2026-65381 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-65381

  1. Install the vendor fixes: update to macOS Sequoia 15.8, Tahoe 26.7, or Golden Gate 27 as appropriate.
  2. Block or restrict execution of untrusted apps via Gatekeeper, MDM policies, or application whitelisting.
  3. Monitor endpoints for unknown or suspicious local applications and unusual post‑execution activity.
  4. Follow Apple’s security guidance and apply OS updates promptly across affected devices.

Frequently asked questions

Is CVE-2026-65381 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which macOS versions are affected by CVE-2026-65381?

The issue affects macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27.

Is there a patch for CVE-2026-65381?

Yes. Apple released fixes in macOS Sequoia 15.8, Tahoe 26.7, and Golden Gate 27.

Does CVE-2026-65381 require authentication?

Exploitation requires a malicious app to run on the target macOS device; it does not require a network login but does require execution of the crafted app.

References