In April 2024, Microsoft uncovered a vulnerability in macOS that could allow specially crafted codes to escape the App Sandbox and run unrestricted on the system.
An attacker could create an exploit to escape the App Sandbox without user interaction required for any sandboxed app using security-scoped bookmarks. With the ability to run code unrestricted on the affected device, attackers could perform further malicious actions like elevating privileges, exfiltrating data, and deploying additional payloads. Microsoft’s Threat Intelligence research demonstrates that these exploits would need to be complex, and require Office macros to be enabled, in order to successfully target the Microsoft Office app. Similar to our discovery of another sandbox escape vulnerability in 2022, Microsoft researchers uncovered this issue while researching potential methods to run and detect malicious macros in Microsoft Office on macOS.
Read more…
Source: Microsoft
Sign up for our Newsletter
The latest news and insights delivered right to your inbox.
Related:
- Update Chrome and ChromeOS to fix critical security issues
October 7, 2026
Google has released updates for the Chrome browser and the ChromeOS operating system. On October 6, Google released a Stable Channel Update for Desktop. This is the most important one for desktop users. It brings Chrome to version 155.0.8059.39 for Linux and versions 154.0.8037.39/.40 for Windows and Mac. The update includes 247 security fixes including four rated Critical. On the same ...
- Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
October 2, 2026
Epic, the software technology giant that makes the widely used MyChart software for accessing patients’ medical data, has paused most of its product development as the company works to protect its software and systems from cyberattacks. Judy Faulkner, the founder and chief executive of Epic, told Modern Healthcare last month that the pause would likely last ...
- Fortinet sounds the alarm over actively exploited FortiMail zero-day
October 2, 2026
Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet’s email security platform. Fortinet describes the vulnerability as a combination of path traversal and ...
- Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
September 29, 2026
Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it may have been used in highly targeted attacks against iPhone users running versions of iOS before iOS 27. The fix is in iOS and iPadOS 26.7.1, ...
- Pentagon breach exposed sensitive data on nearly 3 million people
September 29, 2026
A breach of the Pentagon’s sprawling personnel database exposed sensitive information belonging to a massive swath of military personnel, including Social Security numbers and details about the jobs they held, according to a U.S. defense official. The breach affected 2.76 million living people and another 294,000 who are deceased, the official said. The scope and sensitivity ...
- Fake iPhone Duo preorder scam triggers DarkSword attack
September 29, 2026
Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it. Most of what MalwareBytes researchers found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud. But one fake preorder page was different. Read more… Source: MalwareBytes Labs Sign up for the Cyber Security Review ...
