A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.5. A sandboxed process may be able to circumvent sandbox restrictions.
No PoCs from references.
- https://github.com/gergelykalman/CVE-2023-32364-macos-app-sandbox-escape
- https://github.com/houjingyi233/macOS-iOS-system-security
- https://github.com/jp-cpe/retrieve-cvss-scores
- https://github.com/nomi-sec/PoC-in-GitHub