Microsoft has published an exploit for a vulnerability in macOS that could help an attacker bypass sandbox restrictions and execute code on the system.
See also: Privacy Sandbox: Google tests FLoC technology

The company published the technical details for the security issue, currently known as CVE-2022-26706 , and explained how macOS App Sandbox rules could be circumvented to allow malicious macro code in Word to execute commands on the machine.
Abusing macros in Office to deploy malware has long been an effective and popular technique for compromising Windows.
As the company states, the same could be achieved on macOS machines that lack the appropriate security updates.
Jonathan Bar Or of the Microsoft 365 Defender research team explains that the vulnerability was discovered while examining methods for executing and detecting malicious macros in Microsoft Office documents on macOS.
To ensure compatibility, Microsoft Word can read and write files that have the “~$” prefix, which is defined in the application sandbox rules.
See also: macOS: Will soon block unknown USB-C accessories by default

After studying past reports of macOS sandbox escapes, researchers found that using Startup Services to execute an open –stdin on a special Python with the aforementioned prefix allows escape from the App Sandbox on macOS, potentially leading to system.
The researchers came up with a proof-of-concept (PoC) of the exploit that used the -stdin option for the open command in a Python file to bypass the extended “com.apple.quarantine” feature restriction.
The demonstration exploit code is as simple as dropping a Python file containing arbitrary commands and having the special Word prefix in its name.
Using the open -stdin command starts the Python application with the specially created file as standard input.
"Python executes our code, and since it's a child startup process, it's not bound by Word's sandbox rules," explains Jonathan Or Bar.
The researchers even managed to compress the exploit code so much that it fit into a tweet.
See also: Apple introduces Rapid Security Response for iOS and macOS
Microsoft reported the vulnerability to Apple last October and released a fix with macOS security updates in May 2022 (Big Sur 11.6.6)
Credit for responsibly disclosing the issue is shared with another security researcher, Arsenii Kostromin.
