A researcher has discovered multiple new sandbox escape vulnerabilities in macOS, allowing attackers to gain enhanced execution capabilities and broader file access permissions. The vulnerabilities exist in XPC services, which are used for inter-process communication, and can be exploited by sandboxed applications. The researcher found that many XPC services are reachable from sandboxed applications, despite being intended to be private. The vulnerabilities have been reported to Apple and some have been patched.