Sandbox permission answers must come back from the same machine that asked.
What's wrong with this entry?
When a sandboxed agent asks for a permission decision, the code that collects answers now checks that the answer came back for the same host that made the request, not just the same request id. A mismatched answer is refused and logged. Always on.
- Previously only the request id was compared, so an answer produced on another machine could be applied.
- Hardening only; there is no flag and no behaviour change when everything matches.
answered for a different host
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox