Analyzing CVE-2025-31191: A macOS security-scoped bookmarks-based sandbox escape
ID: 052a3c99-370b-5aa4-8796-6df4c9778cec
STIX ID: report--052a3c99-370b-5aa4-8796-6df4c9778cec
Feed Name: Microsoft Security
Microsoft Threat Intelligence describes discovery and analysis of CVE-2025-31191, a macOS App Sandbox escape that allows sandboxed apps using security-scoped bookmarks to gain arbitrary file access by deleting and replacing the ScopedBookmarkAgent signing secret in the keychain, forging bookmark entries, and obtaining sandbox extension tokens without user interaction; the blog details the technical steps, detection via Microsoft Defender for Endpoint, and notes Apple released a fix on March 31, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
