Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://support.apple.com/en-us/149035 |
|
Sun, 20 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Handling Failure Enables Sandbox Breakout on macOS |
Thu, 17 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 16 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Handling Improves Allowing Sandbox Breakout in macOS | |
| Weaknesses | CWE-22 CWE-363 |
Tue, 15 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Handling Improves Allowing Sandbox Breakout in macOS | |
| Weaknesses | CWE-22 CWE-363 |
Tue, 15 Sep 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos |
|
| Vendors & Products |
Apple
Apple macos |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-09-17T17:20:45.568Z
Reserved: 2026-09-01T21:13:17.757Z
Link: CVE-2026-84584
Updated: 2026-09-17T17:20:26.279Z
Status : Modified
Published: 2026-09-14T21:17:34.480
Modified: 2026-09-17T18:17:10.893
Link: CVE-2026-84584
No data.
OpenCVE Enrichment
Updated: 2026-09-20T20:15:04Z
-
CWE-59
Improper Link Resolution Before File Access ('Link Following')