Summary
Santa treats files that are not Mach-O executables as out of scope, exempt from execution policy. Its classifier read a fixed-size block from the start of each file to make that determination, and when a file was smaller than that block the read returned nothing rather than the bytes that were present. A complete, runnable executable below the threshold was therefore classified as not a Mach-O, treated as out of scope, and allowed to run without any rule being consulted.
The deeper mistake is that a failure to inspect a file was treated as proof of what the file is. A classifier that cannot read a file's format has not established that the file is out of scope.
Impact
A local user with no special privileges could execute arbitrary unsigned native code on a host where Lockdown should have blocked it. The scope decision is reached before Lockdown's denial of unknown binaries, so no rule needed to exist and no approval was involved.
The executed code runs with the invoking user's existing permissions. This is not a privilege escalation. What is lost is Santa's guarantee that only approved binaries run.
Platform scope
Exploitation requires the host to be able to execute x86_64 code, meaning Intel hardware or Apple silicon with Rosetta 2 installed.
Native arm64 is not affected. Apple silicon uses 16 KiB pages, and segment alignment means a valid arm64 image cannot be small enough to fall below the read size this depends on. The constraint is structural rather than a matter of policy or signing, so Apple silicon hosts without Rosetta 2 are out of reach.
What changes in 2026.7
Small native executables are now recognized as Mach-O files and evaluated against execution policy like any other binary.
Expect executions that previously succeeded to start being blocked. Anything small enough to have been treated as out of scope now needs a rule, and in Lockdown it is denied without one. Reviewing execution telemetry for allows carrying a scope decision rather than a rule will identify what relied on the old behavior, and is worth doing before you upgrade rather than after.
Affected versions
| Field |
Value |
| Affected |
Santa <= 2026.6 |
| Fixed in |
Santa 2026.7 |
| Severity |
Medium, CVSS v4.0 base score 6.8 |
| CVSS |
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE |
CWE-20: Improper Input Validation |
Mitigation
Upgrade to Santa 2026.7 or later. There is no configuration change on affected versions that restores correct classification.
Two things reduce exposure in the meantime:
- Remove or withhold Rosetta 2 where it is not needed. Apple silicon hosts that cannot execute x86_64 code are not reachable by this technique.
- Review execution telemetry for executions that were allowed with a scope decision rather than a rule. On affected versions those events are the ones that would carry this bypass.
Credit
Reported by OpenAI Codex Security, Jamie Brim (@jamieb-oai).
Independently reported by @arthurscchan, @DavidKorczynski, and @AdamKorcz. Per that report, the issue was discovered by Claude, Anthropic's AI assistant, with triage and report authoring by Ada Logics in collaboration with Anthropic Research.
Summary
Santa treats files that are not Mach-O executables as out of scope, exempt from execution policy. Its classifier read a fixed-size block from the start of each file to make that determination, and when a file was smaller than that block the read returned nothing rather than the bytes that were present. A complete, runnable executable below the threshold was therefore classified as not a Mach-O, treated as out of scope, and allowed to run without any rule being consulted.
The deeper mistake is that a failure to inspect a file was treated as proof of what the file is. A classifier that cannot read a file's format has not established that the file is out of scope.
Impact
A local user with no special privileges could execute arbitrary unsigned native code on a host where Lockdown should have blocked it. The scope decision is reached before Lockdown's denial of unknown binaries, so no rule needed to exist and no approval was involved.
The executed code runs with the invoking user's existing permissions. This is not a privilege escalation. What is lost is Santa's guarantee that only approved binaries run.
Platform scope
Exploitation requires the host to be able to execute x86_64 code, meaning Intel hardware or Apple silicon with Rosetta 2 installed.
Native arm64 is not affected. Apple silicon uses 16 KiB pages, and segment alignment means a valid arm64 image cannot be small enough to fall below the read size this depends on. The constraint is structural rather than a matter of policy or signing, so Apple silicon hosts without Rosetta 2 are out of reach.
What changes in 2026.7
Small native executables are now recognized as Mach-O files and evaluated against execution policy like any other binary.
Expect executions that previously succeeded to start being blocked. Anything small enough to have been treated as out of scope now needs a rule, and in Lockdown it is denied without one. Reviewing execution telemetry for allows carrying a scope decision rather than a rule will identify what relied on the old behavior, and is worth doing before you upgrade rather than after.
Affected versions
<= 2026.62026.7CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NMitigation
Upgrade to Santa
2026.7or later. There is no configuration change on affected versions that restores correct classification.Two things reduce exposure in the meantime:
Credit
Reported by OpenAI Codex Security, Jamie Brim (@jamieb-oai).
Independently reported by @arthurscchan, @DavidKorczynski, and @AdamKorcz. Per that report, the issue was discovered by Claude, Anthropic's AI assistant, with triage and report authoring by Ada Logics in collaboration with Anthropic Research.