Vulnerabilities · 5h ago

Homebrew 7.0.0 Closes a Cask Sandbox Escape

Homebrew 7.0.0 closed eight security advisories, and Help Net Security says seven of them were already backported into 6.0.x while the LaunchServices sandbox escape disappears only in 7.0.0. That means most auto-updated installs already had the fixes, but one issue still depended on moving to the new release.

The bug sat in cask handling: a malicious package could use macOS app launching and service connections to get work done outside Homebrew’s install sandbox. Homebrew says 7.0.0 tightens which apps, Mach services, and Unix sockets that path can reach, so the package no longer gets the same escape route.

For teams that treat Homebrew as infrastructure on macOS, the practical split is between backported fixes that may already be present and the one version-specific gap that is not. If a fleet stays below 7.0.0, the sandbox boundary around third-party casks is the part that remains weak.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-09-15

Editions

Related stories