RSSAmplifier

· Sep 16, 2025

cve-2025-43330: breaking out of a sandbox using font files

0
Sign in to vote or save

This page cannot be shown here. You can still read it on the original site — the toolbar below keeps your place in the directory.

tl;dr earlier this year, i discovered that macOS’s genatsdb binary (Generate Apple Type Services Databas, i.e. font processing tool) runs without inheriting sandbox restrictions from its parent processes, creating a universal sandbox escape. this was assigned a CVE by Apple. this meant that any sandbox application could execute genatsdb via polyglot files (which, in my PoC, were…

Read on /posts/sandbox/

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.