logo

Analyzing CVE-2025-31191: A macOS security-scoped bookmarks-based sandbox escape

ID: 052a3c99-370b-5aa4-8796-6df4c9778cec

STIX ID: report--052a3c99-370b-5aa4-8796-6df4c9778cec

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2025-05-01

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes discovery and analysis of CVE-2025-31191, a macOS App Sandbox escape that allows sandboxed apps using security-scoped bookmarks to gain arbitrary file access by deleting and replacing the ScopedBookmarkAgent signing secret in the keychain, forging bookmark entries, and obtaining sandbox extension tokens without user interaction; the blog details the technical steps, detection via Microsoft Defender for Endpoint, and notes Apple released a fix on March 31, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.