Description
The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of launchctl to trigger the launchd daemon's execution of a script file, a related issue to CVE-2011-1516.
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://www.coresecurity.com/content/apple-osx-sandbox-bypass
Scores
EPSS
0.0354
EPSS Percentile
87.9%
Details
CWE
CWE-264
Status
published
Products (9)
apple/mac_os_x
10.5.0
apple/mac_os_x
10.5.1
apple/mac_os_x
10.5.2
apple/mac_os_x
10.5.3
apple/mac_os_x
10.5.4
apple/mac_os_x
10.5.5
apple/mac_os_x
10.5.6
apple/mac_os_x
10.5.7
apple/mac_os_x
10.5.8
Published
Nov 15, 2011
Tracked Since
Feb 18, 2026