Vulnerability Details
Basic Information
| Title | Analyzing CVE-2025-31191: A macOS security-scoped bookmarks-based sandbox escape |
|---|---|
| Type | mssecure |
| Published | 2025-05-01T17:00:00 |
| Last Seen | 2025-05-01T18:18:33 |
| CVSS Score | 8.8 (HIGH) |
CVSS v3 Details
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2021-30864, CVE-2022-26696, CVE-2022-26706, CVE-2025-31191 |
|---|---|
| CWE | |
| Bulletin Family | blog |
Description
In April 2024, Microsoft uncovered a vulnerability in macOS that could allow specially crafted codes to escape the App Sandbox and run unrestricted on the system. An attacker could create an exploit to escape the App Sandbox without…
Impact Assessment
| Base Score | 8.8 |
|---|---|
| Severity | HIGH |